Executive brief
Dovecot is an email server that handles IMAP access for mail clients. An authenticated attacker can craft IMAP LIST commands that consume excessive CPU resources, degrading performance or causing the email service to become unavailable. This requires valid login credentials but can impact all users of the affected mail server.
Technical details
The vulnerability is a CPU exhaustion / denial-of-service flaw in Dovecot's IMAP LIST command handler. An attacker with valid IMAP credentials can issue specially crafted LIST commands that trigger expensive processing, causing CPU consumption and service degradation or denial of service. The attack requires authentication but is network-reachable via the IMAP protocol. Patches are available in Dovecot versions 2.3.22.2, 3.0.7, and 3.1.6 or later.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patches available in versions 2.3.22.2, 3.0.7, and 3.1.6+