Use-After-Free Vulnerability in Open-Xchange Dovecot Mail Server
CVE-2026-42007
9.1CRITICAL
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-42007?
A use-after-free vulnerability exists within the Open-Xchange Dovecot Mail Server when handling Sieve scripts with the editheader extension. An authenticated attacker can exploit this issue to manipulate message delivery processes by executing specially crafted Sieve scripts. This manipulation could lead to memory leaks, corruption during mail delivery, and potential crashes of the mail delivery process. It's advised to disable the Sieve editheader extension and upgrade to the latest non-vulnerable version to mitigate this risk.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
