IMAP Thread Command Vulnerability in Open-Xchange Mail Server
CVE-2026-40017

6.5MEDIUM

What is CVE-2026-40017?

An identified vulnerability allows an attacker to exploit the THREAD command in the Open-Xchange Mail Server. By manipulating message headers to create a collision in an internal hash table, this can lead to excessive CPU consumption whenever the THREAD command is executed on an affected mailbox. While this issue is distinct from other vulnerabilities, such as related CVE-2026-40014, it poses a risk of degradation or denial of service for users. Administrators are advised to monitor for unusual CPU usage, terminate any processes that exhibit compromised behavior, and ensure that any offending messages are removed to mitigate the risk.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.