Executive brief
A vulnerability has been identified in Dovecot, a widely used email server, specifically within its ManageSieve component which allows users to manage their email filtering rules. An attacker can send a specially crafted command to the server that causes the ManageSieve service to crash. This can be used to repeatedly disrupt the service, preventing legitimate users from managing their email settings and potentially impacting overall mail delivery operations.
Technical details
A denial of service vulnerability exists in the Dovecot ManageSieve service due to improper input validation. The root cause is located in the handling of the AUTHENTICATE command when a 'literal' is provided as the SASL initial response. A remote, unauthenticated attacker can exploit this by sending a malformed request to the ManageSieve port, triggering a service crash. This can be performed repeatedly to maintain a denial-of-service state. Red Hat and Open-Xchange have released patches to address this issue; users are advised to upgrade or restrict access to the ManageSieve port (typically 4190).
Affected products
- Open-Xchange Dovecot Pro 2.3.0, 2.3.22.1, 3.0.2, 3.0.5, 3.1.0, 3.1.2, 3.1.3, 3.1.4
- Open-Xchange Dovecot CE 2.4.0, 2.4.1, 2.4.3
- Red Hat Enterprise Linux 8, 10
Timeline
- 2026-03-27: advisory: Initial public release by Open-Xchange
- 2026-05-04: patched: Red Hat released security updates (RHSA-2026:13498)
References
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
- https://access.redhat.com/errata/RHSA-2026:13498
- https://access.redhat.com/errata/RHSA-2026:13830
- https://access.redhat.com/errata/RHSA-2026:13857
- https://access.redhat.com/errata/RHSA-2026:17602
- https://access.redhat.com/errata/RHSA-2026:17625
- https://access.redhat.com/errata/RHSA-2026:17626