PT-2026-83062 · Dovecot · Dovecot

·

CVE-2026-40203

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description When IMAP compression is enabled, the compression state is reused across responses in a session. This causes response sizes to depend on both attacker-supplied mail and other mail within the same mailbox. An attacker capable of sending mail to a user and observing the sizes of that user's IMAP traffic can confirm if the body of a small message matches a guessed text. This can disclose whether a secret-like message body matches a candidate text.
Recommendations Update to version 2.4.5-1.1. Disable IMAP compression.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98274
CVE-2026-40203
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot