Executive brief
Dovecot is an open-source IMAP and POP3 mail server used by organizations to store and retrieve email. An attacker who can send email to a user can craft a malicious message header that causes the IMAP THREAD command to consume excessive CPU resources when a mail client processes the affected mailbox. This can degrade mail service performance or cause a complete denial of service for IMAP users.
Technical details
The vulnerability is a denial-of-service flaw in Dovecot's IMAP THREAD command implementation. An attacker can craft a specially designed message header that triggers algorithmic complexity in the threading logic, causing disproportionate CPU consumption relative to message size. The attack requires the ability to send email to a target mailbox and for a mail client to issue a THREAD command on that mailbox. When triggered, the THREAD operation consumes excessive CPU, potentially degrading or denying service to IMAP users. Patches are available in Dovecot versions 2.3.22.2, 3.0.7, and 3.1.6 and later.
Affected products
- Open-Xchange Dovecot 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, 3.1.0 through 3.1.5
Timeline
- 2026-08-28: disclosed: Public advisory released
- 2026-08-28: patched: Fixed in versions 2.3.22.2, 3.0.7, and 3.1.6