PT-2026-28367 · Dovecot+3 · Dovecot+3

·

CVE-2026-27859

·

Published

2026-01-01

·

Updated

2026-07-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.4.3-1.1
Description A mail message with a large number of RFC 2231 MIME parameters can cause excessive CPU usage in LMTP. A specially crafted message can lead to significant CPU time consumption during mail delivery. No publicly available exploits are known.
Recommendations Upgrade to version 2.4.3-1.1 or later. Limit RFC 2231 MIME parameters in mail messages using MTA capabilities.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10406
CVE-2026-27859
OESA-2026-1849
OPENSUSE-SU-2026:10442-1
OPENSUSE-SU-2026:20554-1
SUSE-SU-2026:1641-1
SUSE-SU-2026:21208-1
USN-8136-1

Affected Products

Dovecot
Linuxmint
Red Os
Ubuntu