Denial of Service Vulnerability in ManageSieve by Open-Xchange
CVE-2026-33605

7.5HIGH

What is CVE-2026-33605?

A vulnerability in ManageSieve allows unauthenticated attackers to disrupt the login process by sending a malformed command. In high-security mode, only the attacker's connection is affected, while in high-performance mode, all connections associated with the ManageSieve login process can be terminated. This can lead to a denial of service for Sieve script management. Organizations are advised to restrict access to the ManageSieve service to trusted clients and update to non-vulnerable versions to mitigate this issue.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.