Open-Xchange OX Dovecot CE
25 known vulnerabilities in Open-Xchange OX Dovecot CE, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-73209 CVSS 6.5 medium An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash…
- CVE-2026-73208 CVSS 7.4 high An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a…
- CVE-2026-52687 CVSS 6.5 medium An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a…
- CVE-2026-52681 CVSS 3.1 low Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by…
- CVE-2026-42395 CVSS 4.3 medium A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following…
- CVE-2026-42393 CVSS 3.1 low The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An…
- CVE-2026-42392 CVSS 4.3 medium An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the…
- CVE-2026-42391 CVSS 7.5 high An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and…
- CVE-2026-42008 CVSS 4.3 medium Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a…
- CVE-2026-42007 CVSS 9.1 critical An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail…
- CVE-2026-40205 CVSS 5.9 medium An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is…
- CVE-2026-40204 CVSS 3.1 low None None None No publicly available exploits are known.
- CVE-2026-40203 CVSS 3.7 low When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both…
- CVE-2026-40019 CVSS 5.9 medium An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop…
- CVE-2026-40018 CVSS 7.4 high None None None No publicly available exploits are known.
- CVE-2026-40017 CVSS 6.5 medium An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which…
- CVE-2026-40015 CVSS 4.3 medium An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can…
- CVE-2026-40014 CVSS 6.5 medium An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the…
- CVE-2026-40013 CVSS 4.3 medium An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds…
- CVE-2026-33607 CVSS 4.3 medium An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP…
- CVE-2026-33606 CVSS 4.8 medium Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync…
- CVE-2026-33605 CVSS 7.5 high An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running…
- CVE-2026-33604 CVSS 5.9 medium An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending…
- CVE-2026-33263 CVSS 4.3 medium When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor…
- CVE-2026-27852 CVSS 7.5 high An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME…