PT-2026-83059 · Dovecot · Dovecot

·

CVE-2026-40017

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description An attacker can send a crafted email with message header values designed to collide in an internal hash table. This causes the IMAP THREAD command to consume CPU resources disproportionate to the message size. When a mail client executes the THREAD command on the affected mailbox, it can lead to performance degradation or a denial of service for the IMAP service.
Recommendations Update to version 2.4.5-1.1. Monitor the system for abnormal CPU usage, terminate the offending process, and remove the malicious message from the affected mailbox.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98286
CVE-2026-40017
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1

Affected Products

Dovecot