DoS Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-33607

4.3MEDIUM

What is CVE-2026-33607?

This vulnerability allows an authenticated attacker to exploit the IMAP LIST command, leading to excessive CPU consumption on affected Dovecot IMAP servers. Such an exploit could result in performance degradation or a complete denial of service, impacting user access to email services. To mitigate this risk, it is essential to monitor CPU usage for abnormal patterns and take preventive actions such as terminating the offending process or locking the compromised account. Additionally, users are strongly advised to upgrade to a patched version of the Dovecot IMAP server to safeguard against this vulnerability.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 3.0.7

OX Dovecot Pro 3.1.0 < 3.1.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.