PT-2026-83052 · Open Xchange Gmbh+6 · Ox Dovecot Ce+4

·

CVE-2026-33604

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
This update for dovecot24 fixes the following issues:
Update to 2.4.5.
  • CVE-2026-33263: submission-login: panic when mail max userip connections is reached (bsc#1276794).
  • CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).
  • CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).
  • CVE-2026-33605: managesieve-login: pre-auth crash (bsc#1276809).
  • CVE-2026-33606: dsync: mail content can cause dsync protocol injection (bsc#1276800).
  • CVE-2026-33607: IMAP LIST match sub() exponential backtracking leading to CPU denial of service (bsc#1276795).
  • CVE-2026-40013: stack buffer underflow in pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT (bsc#1276807).
  • CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).
  • CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812).
  • CVE-2026-40017: CPU DoS via CRC32 hash collision in strmap (bsc#1276813).
  • CVE-2026-40018: MySQL multi-byte escaping performed incorrectly (bsc#1276810).
  • CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815).
  • CVE-2026-40204: lda mailbox autocreate can bypass ACL restrictions (bsc#1276819).
  • CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).
  • CVE-2026-42007: sieve editheader RCE (bsc#1276817).
  • CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824).
  • CVE-2026-42391: imap: pre-login memory/CPU growth with ID command (bsc#1276835).
  • CVE-2026-42392: imap-urlauth leaks memory into user-visible error messages (bsc#1276829).
  • CVE-2026-42393: doveadm password or api key length can be leaked with timing comparisons (bsc#1276827).
  • CVE-2026-52687: imap: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).
  • CVE-2026-42395: single NUL-byte XCLIENT FORWARD payload crashes (bsc#1276826).
  • CVE-2026-52681: sieve resource usage tracking lost when active script changes (bsc#1276828).
  • CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830).
  • CVE-2026-73209: imap-login crash due to self-recursion on zero-output decompress chunks (bsc#1276833).

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98280
CVE-2026-33604
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Ox Dovecot Ce
Ox Dovecot Pro
Dovecot
Dovecot22
Dovecot24