Denial of Service Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-52687
6.5MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-52687?
This vulnerability allows an authenticated user to leverage a specific compression algorithm during an IMAP session, potentially leading to excessive memory usage. By opening multiple connections with this algorithm, an attacker can exhaust the process's memory limit, resulting in the termination of the IMAP service. This can cause significant disruption, affecting service availability for legitimate users. Immediate actions include disabling IMAP compression and limiting concurrent connections to mitigate impact. It is recommended to update to a patched version to ensure continued service integrity.
Affected Version(s)
OX Dovecot CE 2.3.11 < 2.4.5
OX Dovecot Pro 2.3.11 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
