Executive brief
A vulnerability in the Dovecot email server allows an attacker to upload specially crafted scripts that bypass safety limits on processor usage. By exceeding these limits by up to 130 times the intended amount, an attacker can consume excessive server resources. This can lead to significant performance degradation or a complete service outage for other email users.
Technical details
A resource consumption vulnerability (CWE-400) exists in Open-Xchange Dovecot's Sieve script execution engine. An authenticated attacker can upload a malicious Sieve script via the ManageSieve service or local access that bypasses the enforced CPU time limits. The flaw allows scripts to run for up to 130 times the configured limit, enabling a denial-of-service (DoS) condition by degrading server performance. The vulnerability is addressed in Dovecot Pro 3.1.5 and Dovecot CE 2.4.4. Temporary mitigations include disabling the ManageSieve service or restricting local script access.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 through 3.1.4
- Open-Xchange Dovecot CE 2.4.0 through 2.4.3
Timeline
- 2026-05-05: patched: Initial internal release of fix
- 2026-05-12: advisory: Public release of advisory OXDC-ADV-2026-0002
- 2026-05-12: disclosed: NVD publication date