Junglewise Threat Intelligence

CVE-2026-40015: Open-Xchange Dovecot IMAP hibernation denial of service

CVE-2026-40015 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot Pro is an email server component that manages IMAP sessions. An authenticated attacker can open multiple connections and send malformed commands, causing the IMAP hibernation service to crash. This interrupts email access for affected users and degrades mail service availability until the process is restarted.

Technical details

The vulnerability is a denial-of-service flaw in the IMAP hibernation service component. An attacker with valid IMAP credentials can establish multiple connections and transmit invalid commands, triggering an out-of-bounds memory read that crashes the imap-hibernate process. The attack requires authentication and network access to the IMAP service. Successful exploitation causes service interruption for hibernated IMAP sessions. Patches are available in OX Dovecot Pro versions 2.3.22.2, 3.0.7, and 3.1.6 or later.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, 3.1.0 through 3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-26: advisory: Initial advisory release

References

Related threats