Junglewise Threat Intelligence

CVE-2026-40019: Open-Xchange Dovecot ManageSieve infinite loop denial of service

CVE-2026-40019 · Severity: medium · CVSS 5.9 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

Open-Xchange Dovecot Pro is an email server component that manages Sieve mail filtering scripts. An unauthenticated attacker can crash the ManageSieve service by sending a specially crafted truncated quoted argument, causing it to spin in an infinite loop and consume CPU resources. Repeated attacks can exhaust all available CPU on the server, rendering the email filtering service unavailable and degrading overall server performance.

Technical details

The vulnerability is a denial-of-service condition in the ManageSieve login process caused by improper handling of truncated quoted arguments. An unauthenticated, network-reachable attacker can trigger an infinite loop in the string parsing logic by sending a malformed quoted string parameter during authentication. No authentication is required to exploit this issue. The attack causes the affected ManageSieve process to consume CPU until manually killed, and multiple connections can exhaust server resources entirely. Patches are available in versions 2.3.22.2, 3.0.7, and 3.1.6 or later.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Patches available in versions 2.3.22.2, 3.0.7, and 3.1.6

References

Related threats