Denial of Service Vulnerability in Dovecot IMAP by Open-Xchange
CVE-2026-52687

6.5MEDIUM

What is CVE-2026-52687?

This vulnerability allows an authenticated user to leverage a specific compression algorithm during an IMAP session, potentially leading to excessive memory usage. By opening multiple connections with this algorithm, an attacker can exhaust the process's memory limit, resulting in the termination of the IMAP service. This can cause significant disruption, affecting service availability for legitimate users. Immediate actions include disabling IMAP compression and limiting concurrent connections to mitigate impact. It is recommended to update to a patched version to ensure continued service integrity.

Affected Version(s)

OX Dovecot CE 2.3.11 < 2.4.5

OX Dovecot Pro 2.3.11 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.