Dovecot · Dovecot · CVE-2026-27858
**Name of the Vulnerable Software and Affected Versions**
Dovecot versions prior to 2.4.3
**Description**
An attacker can send a crafted message before authentication, leading to excessive memory allocation within the managesieve component. This can cause the `managesieve-login` process to crash, potentially resulting in a denial-of-service condition. No publicly available exploits are currently known.
**Recommendations**
Update to version 2.4.3 or later. Protect access to the managesieve protocol.