Executive brief
A vulnerability in the Dovecot email server's ManageSieve component allows an unauthenticated attacker to crash the service. By sending a specially crafted message, an attacker can force the system to exhaust its memory, leading to a denial of service. This prevents legitimate users from managing their email filters and can impact overall mail server availability.
Technical details
This vulnerability is classified as uncontrolled resource consumption (CWE-400/CWE-770) within the ManageSieve component of Dovecot. An attacker can trigger the flaw by sending a specifically crafted message during the pre-authentication phase of a connection. This causes the managesieve-login process to allocate an excessive amount of memory, leading to a crash. Repeated exploitation can result in a sustained denial of service (DoS) for the ManageSieve protocol. Patches are available from Open-Xchange and Red Hat (e.g., RHSA-2026:13498).
Affected products
- Open-Xchange Dovecot Pro 2.3.0, 2.3.22.1, 3.0.2, 3.0.5, 3.1.0, 3.1.2, 3.1.3, 3.1.4
- Open-Xchange Dovecot CE 2.4.0, 2.4.1, 2.4.3
- Red Hat Enterprise Linux 8, 10, 10.2
Timeline
- 2026-03-27: advisory: Initial release of OXDC-ADV-2026-0001
- 2026-05-04: patched: Red Hat released security updates for RHEL 10
References
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
- https://access.redhat.com/errata/RHSA-2026:13498
- https://access.redhat.com/errata/RHSA-2026:13830
- https://access.redhat.com/errata/RHSA-2026:13857
- https://access.redhat.com/errata/RHSA-2026:17602
- https://access.redhat.com/errata/RHSA-2026:17625
- https://access.redhat.com/errata/RHSA-2026:17626