DoS Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-33607
4.3MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-33607?
This vulnerability allows an authenticated attacker to exploit the IMAP LIST command, leading to excessive CPU consumption on affected Dovecot IMAP servers. Such an exploit could result in performance degradation or a complete denial of service, impacting user access to email services. To mitigate this risk, it is essential to monitor CPU usage for abnormal patterns and take preventive actions such as terminating the offending process or locking the compromised account. Additionally, users are strongly advised to upgrade to a patched version of the Dovecot IMAP server to safeguard against this vulnerability.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 3.0.7
OX Dovecot Pro 3.1.0 < 3.1.6
