Denial of Service Vulnerability in Dovecot by Open-Xchange
CVE-2026-42395

4.3MEDIUM

What is CVE-2026-42395?

A vulnerability exists in Dovecot that allows a compromised or malicious trusted proxy to send forwarding information with a NUL byte. This input can disrupt the login process, terminating it unexpectedly and leading to potential denial of service for users attempting to log in. To mitigate the risk, it is crucial to carefully restrict the list of trusted proxy networks, only including those that are fully managed and controlled by your organization. Regularly updating to the latest non-vulnerable version of Dovecot is essential for ensuring continued security.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.