Junglewise Threat Intelligence

CVE-2026-42006: Open-Xchange Dovecot uncontrolled memory consumption in IMAP

CVE-2026-42006 · Severity: medium · CVSS 4.3 · Published 2026-05-12

Technologies: Open-Xchange Dovecot CE, Dovecot, Open-Xchange Dovecot Pro. Vendors: Open-Xchange, Dovecot.

Executive brief

Open-Xchange Dovecot is a widely used email server. A vulnerability in its IMAP handling allows an attacker to send specially crafted commands that consume excessive server memory. This can lead to a denial-of-service condition where the email service becomes slow or unavailable for other users.

Technical details

This vulnerability is a resource exhaustion issue (CWE-400) in the IMAP component of Dovecot. It stems from an incomplete fix for CVE-2026-27857; while closing braces were previously restricted, an attacker can still use excessive open braces to bypass memory allocation limits. A remote attacker with basic user privileges can send these crafted IMAP commands to consume memory up to the configured process limit, potentially causing a denial of service. The issue is resolved in Dovecot Pro 3.1.5 and Dovecot CE 2.4.4. As a workaround, administrators can configure a low 'vsz_limit' for the IMAP process.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0, 3.0.5, 3.1.0, 3.1.4
  • Open-Xchange Dovecot CE 2.4.0, 2.4.3

Timeline

  • 2026-05-12: advisory: Initial public release of the advisory
  • 2026-05-12: disclosed: NVD publication date

References

Related threats