Executive brief
OX Dovecot Pro is an IMAP email server used to handle incoming and outgoing mail for organizations. An authenticated attacker can send specially crafted compressed data that exhausts the server's stack memory, causing the IMAP process to crash and resulting in email service unavailability for affected users.
Technical details
This vulnerability is a stack exhaustion flaw triggered by malformed compressed data in the IMAP protocol. An attacker with valid IMAP credentials can exploit this by sending crafted compressed payloads that cause recursive or deep stack consumption, leading to a crash of the IMAP daemon process. The attack requires authentication, limiting exposure to users with valid accounts or to scenarios where credential compromise has occurred. The result is a denial of service: the IMAP service becomes unavailable until the process is manually or automatically restarted. Patches are available in OX Dovecot Pro versions 2.3.22.2, 3.0.7, and 3.1.6 or later.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, 3.1.0 through 3.1.5
Timeline
- 2026-08-28: disclosed
- 2026-08-26: advisory: OXDC-ADV-2026-0003 initial release