PT-2026-83053 · Dovecot · Dovecot
CVE-2026-33605
·
Published
2026-08-28
·
Updated
2026-09-02
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
An unauthenticated attacker can cause a denial of service for Sieve script management by sending a small malformed command before authentication, which crashes the ManageSieve login process. The impact depends on the operating mode: in high-security mode, only the attacker's connection is terminated, whereas in high-performance mode, all connections handled by the same managesieve-login process are terminated.
Recommendations
Update to version 2.4.5-1.1.
Restrict network access to the ManageSieve service to trusted clients.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot