CVE-2026-27858
EUVD-2026-1656927.03.2026, 09:16
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dovecot | dovecot | 𝑥 < 2.4.3 |
| open-xchange | dovecot | 𝑥 < 2.3.22.1 |
| open-xchange | dovecot | 3.0.0 ≤ 𝑥 < 3.0.5 |
| open-xchange | dovecot | 3.1.0 ≤ 𝑥 < 3.1.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| dovecot22 |
| ||||
| dovecot22-backend-mysql |
| ||||
| dovecot22-backend-pgsql |
| ||||
| dovecot22-backend-sqlite |
| ||||
| dovecot22-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| dovecot |
| ||||
| dovecot-devel |
| ||||
| dovecot-mysql |
| ||||
| dovecot-pgsql |
| ||||
| dovecot-pigeonhole |
|
Vulnerability Media Exposure