Junglewise Threat Intelligence

CVE-2026-27858: Open-Xchange Dovecot denial of service in ManageSieve

CVE-2026-27858 · Severity: high · CVSS 7.5 · Published 2026-03-27

Technologies: Red Hat Enterprise Linux, Open-Xchange Dovecot CE, Dovecot, Open-Xchange Dovecot Pro. Vendors: Red Hat, Open-Xchange, Dovecot.

Executive brief

A vulnerability in the Dovecot email server's ManageSieve component allows an unauthenticated attacker to crash the service. By sending a specially crafted message, an attacker can force the system to exhaust its memory, leading to a denial of service. This prevents legitimate users from managing their email filters and can impact overall mail server availability.

Technical details

This vulnerability is classified as uncontrolled resource consumption (CWE-400/CWE-770) within the ManageSieve component of Dovecot. An attacker can trigger the flaw by sending a specifically crafted message during the pre-authentication phase of a connection. This causes the managesieve-login process to allocate an excessive amount of memory, leading to a crash. Repeated exploitation can result in a sustained denial of service (DoS) for the ManageSieve protocol. Patches are available from Open-Xchange and Red Hat (e.g., RHSA-2026:13498).

Affected products

  • Open-Xchange Dovecot Pro 2.3.0, 2.3.22.1, 3.0.2, 3.0.5, 3.1.0, 3.1.2, 3.1.3, 3.1.4
  • Open-Xchange Dovecot CE 2.4.0, 2.4.1, 2.4.3
  • Red Hat Enterprise Linux 8, 10, 10.2

Timeline

  • 2026-03-27: advisory: Initial release of OXDC-ADV-2026-0001
  • 2026-05-04: patched: Red Hat released security updates for RHEL 10

References

Related threats