Dovecot · Dovecot · CVE-2026-33606
**Name of the Vulnerable Software and Affected Versions**
dovecot versions prior to 2.4.5-1.1
**Description**
Mail content stored by a user can be crafted to be interpreted as dsync protocol commands when an administrator executes dsync using the stream protocol, such as during migration or replication. This allows for the modification of mailbox states on the destination, including internal mailbox attributes that users should not be able to set directly, and may result in dsync errors.
**Recommendations**
Update to version 2.4.5-1.1.
Avoid running dsync with the stream protocol on mailboxes containing untrusted content.