SMTP Command Injection Vulnerability in Dovecot by Open-Xchange
CVE-2026-33604
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-33604?
This vulnerability allows an attacker to exploit Dovecot's email relay functionality by manipulating message body content. If the attacker successfully crafts a message with specific line endings, they can bypass outbound protections. This could lead a downstream mail server, particularly those that haven’t patched similar SMTP vulnerabilities, to misinterpret sections of the message body as valid SMTP commands. Consequently, this may result in the injection of spoofed emails. It is crucial for organizations managing their email servers to implement strict validation to reject raw carriage returns in message data and promptly update to secured versions of Dovecot.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
