PT-2026-83052 · Open Xchange Gmbh+6 · Ox Dovecot Ce+4
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
This update for dovecot24 fixes the following issues:
Update to 2.4.5.
- CVE-2026-33263:
submission-login: panic whenmail max userip connectionsis reached (bsc#1276794). - CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).
- CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).
- CVE-2026-33605:
managesieve-login: pre-auth crash (bsc#1276809). - CVE-2026-33606:
dsync: mail content can causedsyncprotocol injection (bsc#1276800). - CVE-2026-33607: IMAP
LISTmatch sub()exponential backtracking leading to CPU denial of service (bsc#1276795). - CVE-2026-40013: stack buffer underflow in
pigeonholeManageSieveCHECKSCRIPT/PUTSCRIPT(bsc#1276807). - CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).
- CVE-2026-40015:
imap-hibernatecan be crashed (bsc#1276812). - CVE-2026-40017: CPU DoS via CRC32 hash collision in
strmap(bsc#1276813). - CVE-2026-40018: MySQL multi-byte escaping performed incorrectly (bsc#1276810).
- CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815).
- CVE-2026-40204:
lda mailbox autocreatecan bypass ACL restrictions (bsc#1276819). - CVE-2026-40205: OAuth2
passdbscope enforcement bypass via OR semantics in remote validation path (bsc#1276820). - CVE-2026-42007:
sieveeditheaderRCE (bsc#1276817). - CVE-2026-42008:
XCLIENT FORWARD= baretoken not namespaced (bsc#1276824). - CVE-2026-42391:
imap: pre-login memory/CPU growth withIDcommand (bsc#1276835). - CVE-2026-42392:
imap-urlauthleaks memory into user-visible error messages (bsc#1276829). - CVE-2026-42393:
doveadm passwordor api key length can be leaked with timing comparisons (bsc#1276827). - CVE-2026-52687:
imap:COMPRESS ZSTDcan cause excessive memory usage (bsc#1276837). - CVE-2026-42395: single NUL-byte
XCLIENT FORWARDpayload crashes (bsc#1276826). - CVE-2026-52681:
sieveresource usage tracking lost when active script changes (bsc#1276828). - CVE-2026-73208:
auth:db-oauth2:audclaim used as fallback for missing scope claim (bsc#1276830). - CVE-2026-73209:
imap-logincrash due to self-recursion on zero-output decompress chunks (bsc#1276833).
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox Dovecot Ce
Ox Dovecot Pro
Dovecot
Dovecot22
Dovecot24