Executive brief
OX Dovecot Pro is an email server component that manages IMAP sessions. An authenticated attacker can open multiple connections and send malformed commands, causing the IMAP hibernation service to crash. This interrupts email access for affected users and degrades mail service availability until the process is restarted.
Technical details
The vulnerability is a denial-of-service flaw in the IMAP hibernation service component. An attacker with valid IMAP credentials can establish multiple connections and transmit invalid commands, triggering an out-of-bounds memory read that crashes the imap-hibernate process. The attack requires authentication and network access to the IMAP service. Successful exploitation causes service interruption for hibernated IMAP sessions. Patches are available in OX Dovecot Pro versions 2.3.22.2, 3.0.7, and 3.1.6 or later.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, 3.1.0 through 3.1.5
Timeline
- 2026-08-28: disclosed
- 2026-08-26: advisory: Initial advisory release