Junglewise Threat Intelligence

CVE-2026-73209: Open-Xchange Dovecot stack exhaustion denial of service

CVE-2026-73209 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot Pro is an IMAP email server used to handle incoming and outgoing mail for organizations. An authenticated attacker can send specially crafted compressed data that exhausts the server's stack memory, causing the IMAP process to crash and resulting in email service unavailability for affected users.

Technical details

This vulnerability is a stack exhaustion flaw triggered by malformed compressed data in the IMAP protocol. An attacker with valid IMAP credentials can exploit this by sending crafted compressed payloads that cause recursive or deep stack consumption, leading to a crash of the IMAP daemon process. The attack requires authentication, limiting exposure to users with valid accounts or to scenarios where credential compromise has occurred. The result is a denial of service: the IMAP service becomes unavailable until the process is manually or automatically restarted. Patches are available in OX Dovecot Pro versions 2.3.22.2, 3.0.7, and 3.1.6 or later.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, 3.1.0 through 3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-26: advisory: OXDC-ADV-2026-0003 initial release

References

Related threats