PT-2026-83075 · Dovecot · Dovecot

CVE-2026-73209

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description An attacker with valid credentials can send specially crafted compressed data that leads to stack exhaustion, causing the affected process to crash. This termination of the process can result in service degradation or a denial of service for the IMAP (Internet Message Access Protocol), which is a standard protocol used by email clients to retrieve messages from a mail server.
Recommendations Update to version 2.4.5-1.1.

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98283
CVE-2026-73209
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot