Executive brief
Open-Xchange Dovecot Pro is an email server component that manages Sieve mail filtering scripts. An unauthenticated attacker can crash the ManageSieve service by sending a specially crafted truncated quoted argument, causing it to spin in an infinite loop and consume CPU resources. Repeated attacks can exhaust all available CPU on the server, rendering the email filtering service unavailable and degrading overall server performance.
Technical details
The vulnerability is a denial-of-service condition in the ManageSieve login process caused by improper handling of truncated quoted arguments. An unauthenticated, network-reachable attacker can trigger an infinite loop in the string parsing logic by sending a malformed quoted string parameter during authentication. No authentication is required to exploit this issue. The attack causes the affected ManageSieve process to consume CPU until manually killed, and multiple connections can exhaust server resources entirely. Patches are available in versions 2.3.22.2, 3.0.7, and 3.1.6 or later.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patches available in versions 2.3.22.2, 3.0.7, and 3.1.6