Open Xchange
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Open Xchange product.
RSS Feeds for Open Xchange security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Open Xchange products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Open Xchange Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 41 vulnerabilities in Open Xchange with an average score of 5.8 out of ten. Last year, in 2025 Open Xchange had 7 security vulnerabilities published. That is, 34 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.32
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 41 | 5.77 |
| 2025 | 7 | 6.09 |
| 2024 | 23 | 6.30 |
| 2023 | 47 | 5.70 |
| 2022 | 23 | 6.37 |
| 2021 | 37 | 6.02 |
| 2020 | 14 | 5.36 |
| 2019 | 14 | 6.28 |
| 2018 | 13 | 6.20 |
It may take a day or so for new Open Xchange vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Open Xchange Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-73209 | Aug 28, 2026 |
Dovecot IMAP COMPRESS Stack Exhaustion (CVE-2026-73209)An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-73208 | Aug 28, 2026 |
OAuth2 Audience Claims Misused for Auth in DovecotAn attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-52687 | Aug 28, 2026 |
Open-Xchange IMAP Compression DoS via Memory ExhaustionAn attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-52681 | Aug 28, 2026 |
Dovecot Sieve CPU limit bypass via script reactivationSieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42395 | Aug 28, 2026 |
Null byte injection via trusted proxy causes login crashA host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42393 | Aug 28, 2026 |
TimingAttack on Dovecot doveadm Password/API Key Length LeakThe comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42392 | Aug 28, 2026 |
IMAP URLFETCH Uninitialized Memory Disclosure in DovecotAn attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42391 | Aug 28, 2026 |
IMAP ID DoS via large param list in Dovecot login processAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42008 | Aug 28, 2026 |
Dovecot Trusted Proxy Auth InjectionForwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42007 | Aug 28, 2026 |
Use-After-Free in Dovecot Sieve Editheader Extension via Authenticated ScriptAn attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40205 | Aug 28, 2026 |
OAuth2 Partial Scope Validation Bypass in Remote CheckAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40204 | Aug 28, 2026 |
Unknown product: CVE-2026-40204 potential vulnerabilityNone None None No publicly available exploits are known. |
|
| CVE-2026-40203 | Aug 28, 2026 |
IMAP Compression State Reuse Leak in Dovecot (CVE-2026-40203)When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40019 | Aug 28, 2026 |
Dovecot ManageSieve Infinite Loop DoSAn unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40018 | Aug 28, 2026 |
CVE202640018: Generic Security VulnerabilityNone None None No publicly available exploits are known. |
|
| CVE-2026-40017 | Aug 28, 2026 |
IMAP THREAD Header Hash Collision DoS in DovecotAn attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40015 | Aug 28, 2026 |
Out-of-Bounds Read Crash via IMAP Hibernation (CVE-2026-40015)An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40014 | Aug 28, 2026 |
IMAP THREAD CPU DoS via Header CraftingAn attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-40013 | Aug 28, 2026 |
Dovecot ManageSieve OOB Write via Extreme Numeric LiteralAn attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-33607 | Aug 28, 2026 |
IMAP LIST CPU DoS via Authenticated UserAn attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known. |
|
| CVE-2026-33606 | Aug 28, 2026 |
Zimbra DSync Stream Protocol Command InjectionMail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-33605 | Aug 28, 2026 |
ManageSieve DoS via malformed command CVE-2026-33605An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-33604 | Aug 28, 2026 |
CVE-2026-33604: Dovecot SMTP Smuggling via Crafted Body InjectionAn attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in message data. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-33263 | Aug 28, 2026 |
Epoll Panic in Submission-Login (mail_max_userip_connections)When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If running in high-performance mode (default for Pro releases), all connections handled by the submission-login process will be terminated. The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent. If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen, because the crash can only happen at AUTH stage. Limit the number of connections handled by single submission-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-27852 | Aug 28, 2026 |
Memory Exhaustion via Large IMAP Header in OX App SuiteAn attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known. |
|
| CVE-2026-42006 | May 12, 2026 |
Uncontrolled Mem Usage via Excessive Bracing in OpenBSD IMAPAn attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known. |
|
| CVE-2026-40020 | May 12, 2026 |
Dovecot SETACL Injection Enables "anyone" ACLAttacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known. |
|
| CVE-2026-40016 | May 12, 2026 |
Dovecot ManageSieve CPU limit bypass via malicious script uploadAttacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known. |
|
| CVE-2026-33603 | May 12, 2026 |
Dovecot Base64 SCRAM TLS Binding Spoof (MITM)Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known. |
|
| CVE-2026-27851 | May 12, 2026 |
Jinja2 Safe Filter Pipeline Escaping Bypass (CVE-2026-27851)When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known. |
|
| CVE-2026-27860 | Mar 27, 2026 |
LDAP Filter Injection in Dovecot Auth via Empty auth_username_charsIf auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known. |
|
| CVE-2026-27859 | Mar 27, 2026 |
Excessive RFC2231 MIME Parameters cause LMTP CPU exhaustion in PostfixA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available exploits are known. |
|
| CVE-2026-27858 | Mar 27, 2026 |
DoS via Memory Exhaustion in managesieve (Dovecot)Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known. |
|
| CVE-2026-27857 | Mar 27, 2026 |
NOOP Command Parenthesis Overflow Causes 1GB Mem DoSSending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known. |
|
| CVE-2026-27856 | Mar 27, 2026 |
Dovecot doveadm Timing Oracle Attack Exposes CredentialsDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known. |
|
| CVE-2026-27855 | Mar 27, 2026 |
Dovecot OTP Replay via Auth CachingDovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known. |
|
| CVE-2026-24031 | Mar 27, 2026 |
Dovecot Auth Bypass via Clearing auth_username_chars (SQL Auth)Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known. |
|
| CVE-2026-0394 | Mar 27, 2026 |
Dovecot Path-Traversal: Per-Domain Auth Files Read /etc/passwdWhen dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known. |
|
| CVE-2025-59032 | Mar 27, 2026 |
ManageSieve AUTHENTICATE Crash via Literal SASL Initial ResponseManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known. |
|
| CVE-2025-59031 | Mar 27, 2026 |
Dovecot FTS Script Mishandles ZIP Attachments, Enables OOXML IndexingDovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. |
|
| CVE-2025-59028 | Mar 27, 2026 |
DoS via Invalid Base64 SASL Data Disconnects Auth SessionsWhen sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known. |
|
| CVE-2025-59026 | Nov 27, 2025 |
File Upload XSS: Malicious Content Triggers Script Execution in User ContextMalicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available exploits are known |
|
| CVE-2025-59025 | Nov 27, 2025 |
Email XSS: Malicious Script Execution via Sanitization BypassMalicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known |
|
| CVE-2025-30190 | Nov 27, 2025 |
Office Doc Scripting Injection Vulnerability (CVE-2025-30190)Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available exploits are known |
|
| CVE-2025-30186 | Nov 27, 2025 |
CVE-2025-30186: File Upload XSS Causing Script ExecutionMalicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No publicly available exploits are known |
|
| CVE-2025-30189 | Oct 31, 2025 |
Linux PAM Passdb/Userdb Drivers Use Same Cache Key User HijackingWhen cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known. |
|
| CVE-2025-30191 | Oct 31, 2025 |
Unknown: EMail Redirection Attack via Malicious ContentMalicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known |
|
| CVE-2025-30188 | Oct 31, 2025 |
Unknown: API-induced Cache Eviction DoS via Unbounded Data AdditionMalicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No publicly available exploits are known |
|
| CVE-2024-23184 | Sep 10, 2024 |
Dovecot DoS via Large Address Header ParsingHaving a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known. |
|
| CVE-2024-23185 | Sep 10, 2024 |
Dovecot Message-Parser DoS via Large HeadersVery large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general). One can implement restrictions on headers on MTA component preceding Dovecot. No publicly available exploits are known. |
|