Denial of Service Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-42391

7.5HIGH

What is CVE-2026-42391?

An unauthenticated attacker can exploit the Dovecot IMAP service by sending an excessively large number of parameters through the IMAP ID command prior to authentication. This exploit leads to increased memory and CPU utilization, potentially overwhelming the login process, which results in service degradation or full denial of service for IMAP logins. The exploited process may also terminate other active connections, exacerbating the disruption. It is essential for users to limit the number of concurrent connections handled by a single imap-login process and to upgrade to a patched version to mitigate this vulnerability.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.