Executive brief
OX Dovecot Pro is an email server that handles user authentication and mail operations. A trusted proxy host can send specially crafted forwarding information containing a NUL byte, which crashes the login process and prevents users from authenticating. This causes service unavailability for affected users. Only deployments that explicitly configure trusted proxy networks are vulnerable.
Technical details
The vulnerability is a denial-of-service condition in OX Dovecot Pro's login process triggered by malformed forwarding headers from a host configured as a trusted proxy. When a trusted proxy sends forwarding information containing a NUL byte, the login process crashes on the next authentication attempt, terminating the session. The attack vector is network-based and requires the attacker to control or compromise a host listed in the trusted proxy configuration. No publicly available exploits are known. Affected versions: 2.3.0–2.3.22.1, 3.0.0–3.0.6, and 3.1.0–3.1.5; patched versions are 2.3.22.2, 3.0.7, and 3.1.6.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5
Timeline
- 2026-08-28: disclosed: CVE-2026-42395 publicly disclosed