CVE-2026-27858
HIGHOX Dovecot Pro < 2.3.0, < 3.1.0, < 2.4.0 - Unauthenticated Denial of Service via Managesieve Memory Allocation
Title source: llmDescription
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
Scores
CVSS v3
7.5
EPSS
0.0046
EPSS Percentile
36.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (5)
dovecot/dovecot
< 2.4.3
open-xchange/dovecot
< 2.3.22.1
Open-Xchange GmbH/OX Dovecot Pro
< 2.3.0
Open-Xchange GmbH/OX Dovecot Pro
< 2.4.0
Open-Xchange GmbH/OX Dovecot Pro
< 3.1.0
Published
Mar 27, 2026
Tracked Since
Mar 27, 2026