Dovecot · Dovecot · CVE-2026-52687
**Name of the Vulnerable Software and Affected Versions**
dovecot versions prior to 2.4.5-1.1
**Description**
An attacker with valid credentials can cause a denial of service for IMAP by selecting a compression algorithm for the connection that requires excessive memory for its decompression state. By opening several such connections, the process memory limit is reached, resulting in the termination of the process and all associated connections.
**Recommendations**
Update to version 2.4.5-1.1.
Disable IMAP compression.
Limit the number of connections handled by a single imap-login process.