PT-2026-83053 · Dovecot · Dovecot

CVE-2026-33605

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description An unauthenticated attacker can cause a denial of service for Sieve script management by sending a small malformed command before authentication, which crashes the ManageSieve login process. The impact depends on the operating mode: in high-security mode, only the attacker's connection is terminated, whereas in high-performance mode, all connections handled by the same managesieve-login process are terminated.
Recommendations Update to version 2.4.5-1.1. Restrict network access to the ManageSieve service to trusted clients.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98259
CVE-2026-33605
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot