Denial of Service Vulnerability in Dovecot by Open-Xchange
CVE-2026-42395
4.3MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-42395?
A vulnerability exists in Dovecot that allows a compromised or malicious trusted proxy to send forwarding information with a NUL byte. This input can disrupt the login process, terminating it unexpectedly and leading to potential denial of service for users attempting to log in. To mitigate the risk, it is crucial to carefully restrict the list of trusted proxy networks, only including those that are fully managed and controlled by your organization. Regularly updating to the latest non-vulnerable version of Dovecot is essential for ensuring continued security.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
