Denial of Service Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-42391
7.5HIGH
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-42391?
An unauthenticated attacker can exploit the Dovecot IMAP service by sending an excessively large number of parameters through the IMAP ID command prior to authentication. This exploit leads to increased memory and CPU utilization, potentially overwhelming the login process, which results in service degradation or full denial of service for IMAP logins. The exploited process may also terminate other active connections, exacerbating the disruption. It is essential for users to limit the number of concurrent connections handled by a single imap-login process and to upgrade to a patched version to mitigate this vulnerability.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
