Use-After-Free Vulnerability in Open-Xchange Dovecot Mail Server
CVE-2026-42007

9.1CRITICAL

What is CVE-2026-42007?

A use-after-free vulnerability exists within the Open-Xchange Dovecot Mail Server when handling Sieve scripts with the editheader extension. An authenticated attacker can exploit this issue to manipulate message delivery processes by executing specially crafted Sieve scripts. This manipulation could lead to memory leaks, corruption during mail delivery, and potential crashes of the mail delivery process. It's advised to disable the Sieve editheader extension and upgrade to the latest non-vulnerable version to mitigate this risk.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.