HarborGuard / CVE
Back to search
HIGHCVE-2026-27858Published Modified CNA OX

CVE-2026-27858: Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Open-Xchange GmbH / OX Dovecot Pro
    ≤ 2.3.0 · ≤ 3.1.0 · ≤ 2.4.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H