Junglewise Threat Intelligence

CVE-2026-40203: Open-Xchange Dovecot IMAP compression information disclosure

CVE-2026-40203 · Severity: low · CVSS 3.7 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

Dovecot is an email server component that handles IMAP mail access. When IMAP compression is enabled, the server reuses the same compression state across multiple responses in a session, causing response sizes to leak information about mail content. An attacker who can send mail to a user and monitor their IMAP traffic can use response size variations to confirm whether specific message bodies match guessed text, potentially exposing confidential email content.

Technical details

This vulnerability is an information disclosure issue in Dovecot's IMAP compression implementation. The root cause is that compression state is reused across responses rather than being reset between messages, making response sizes dependent on both attacker-controlled content and other mail in the mailbox. The attack requires network access to observe IMAP traffic and the ability to send mail to the target user. An attacker can perform a compression side-channel attack to confirm whether a message body matches a candidate plaintext (e.g., a password or secret phrase), though recovery of arbitrary unknown content was not demonstrated. Patches are available in Dovecot 2.3.22.2, 3.0.7, and 3.1.6 or later; workaround is to disable IMAP compression.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 to <2.3.22.2, 3.0.0 to <3.0.7, 3.1.0 to <3.1.6

Timeline

  • 2026-08-28: disclosed

References

Related threats