PT-2026-83061 · Dovecot · Dovecot

·

CVE-2026-40019

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description An unauthenticated attacker can cause a denial of service by sending a truncated quoted argument to the ManageSieve login process. This action triggers an infinite loop that consumes CPU resources, leading to the degradation of Sieve script management or a complete server crash if repeated connections are made.
Recommendations Update to version 2.4.5-1.1. Monitor the system for abnormal CPU usage and terminate the offending process. Restrict network access to the ManageSieve service to trusted clients.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40019
OPENSUSE-SU-2026:11629-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot