IMAP Compression Vulnerability in Dovecot Mail Server by Open-Xchange
CVE-2026-40203
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-40203?
The vulnerability in Dovecot Mail Server arises when IMAP compression is enabled, causing the same compression state to be reused across responses during a session. This can lead to potential information leakage, as attackers who can observe the sizes of IMAP traffic may verify whether the body of a small message corresponds to a guessed text. Although recovery of arbitrary unknown content is not demonstrated, the risk of confirming the match between a candidate message and the body of a secret-like message poses a significant concern for data privacy. To mitigate this risk, it is advised to disable IMAP compression and ensure the server is updated to a secure version.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
