SMTP Command Injection Vulnerability in Dovecot by Open-Xchange
CVE-2026-33604

5.9MEDIUM

What is CVE-2026-33604?

This vulnerability allows an attacker to exploit Dovecot's email relay functionality by manipulating message body content. If the attacker successfully crafts a message with specific line endings, they can bypass outbound protections. This could lead a downstream mail server, particularly those that haven’t patched similar SMTP vulnerabilities, to misinterpret sections of the message body as valid SMTP commands. Consequently, this may result in the injection of spoofed emails. It is crucial for organizations managing their email servers to implement strict validation to reject raw carriage returns in message data and promptly update to secured versions of Dovecot.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.