Submission-Login Process Vulnerability in Open-Xchange Dovecot Email Server
CVE-2026-33263

4.3MEDIUM

What is CVE-2026-33263?

The Dovecot Email Server can experience a crashing issue within its submission-login process when the maximum number of user IP connections is reached. This flaw arises due to improper handling of file descriptors, particularly when the 'mail_max_userip_connections' setting is exceeded. In high-security mode, the new connection is terminated, while in high-performance mode, all connections managed by this process may be dropped. Users may face difficulties sending messages or encounter duplicate message deliveries. To mitigate this issue, limiting the number of connections per submission-login process is advised, although this may impact performance. An update to a secure version is necessary, and currently, there are no publicly known exploits.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.