CVE-2026-27852
7.5Open-Xchange · OX Dovecot Pro and OX Dovecot CE
A resource exhaustion vulnerability in OX Dovecot allows unauthenticated remote attackers to trigger a denial of service by sending specially crafted email messages that consume excessive memory.
Executive summary
A critical denial of service vulnerability in Open-Xchange OX Dovecot Pro and CE allows unauthenticated attackers to crash IMAP processes via maliciously crafted email headers.
Vulnerability
The software contains a vulnerability categorized as CWE-400, specifically uncontrolled resource consumption, where the IMAP parser fails to properly handle messages containing an excessive number of email addresses or MIME parameters, leading to process termination. This attack is unauthenticated and can be triggered remotely by any sender capable of delivering mail to the target server.
Business impact
The successful exploitation of this vulnerability results in a denial of service for affected users, rendering their mailboxes unreachable via IMAP. Given the high CVSS score of 7.5, this flaw represents a significant threat to operational continuity, as an attacker could disrupt critical communication channels or impact service availability for entire user groups with minimal effort.
Remediation
Immediate Action: Upgrade to the latest secure version of OX Dovecot Pro or CE as specified in the official vendor advisory to resolve the memory exhaustion flaw.
Proactive Monitoring: Review IMAP server logs for repeated process crashes or anomalous memory usage patterns that may indicate attempts to trigger this denial of service.
Compensating Controls: Implement strict email filtering and size limits on incoming messages at the gateway level to prevent malformed or overly large headers from reaching the Dovecot service.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing affected versions of OX Dovecot must prioritize the vendor-provided patches to ensure system stability. Because this vulnerability is automatable and requires no authentication, the risk of exploitation is elevated for internet-facing mail servers. Apply the recommended updates immediately to prevent potential service downtime.