Dovecot · Dovecot · CVE-2026-40015
**Name of the Vulnerable Software and Affected Versions**
dovecot versions prior to 2.4.5-1.1
**Description**
An attacker with valid credentials can establish multiple connections to the imap-hibernate service and send invalid commands. This action can trigger an intermittent out-of-bounds read, leading to a process crash. Such crashes interrupt hibernated IMAP sessions, resulting in a degradation of IMAP service. An out-of-bounds read occurs when the software reads data past the end of the intended buffer, potentially accessing restricted memory.
**Recommendations**
Update to version 2.4.5-1.1.
Disable IMAP hibernation.