PT-2026-40030 · Dovecot+4 · Dovecot+4

·

CVE-2026-42006

·

Published

2026-05-12

·

Updated

2026-07-28

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.4-1.1
Description An attacker can cause uncontrolled memory usage via excessive bracing over IMAP. A previous fix was incomplete as it only blocked closing braces, allowing the memory limit to be bypassed using open braces. This can lead to memory consumption reaching the configured limit.
Recommendations Update to version 2.4.4-1.1. Configure vsz limit for the imap process to a low value.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:41905
ALSA-2026:41988
ALSA-2026:46532
BDU:2026-10389
CVE-2026-42006
OESA-2026-2722
OPENSUSE-SU-2026:10766-1
OPENSUSE-SU-2026:21109-1
RHSA-2026:41905
RHSA-2026:41988
RHSA-2026:42091
SUSE-SU-2026:22185-1
SUSE-SU-2026:2645-1
USN-8365-1

Affected Products

Dovecot
Linuxmint
Red Os
Rocky Linux
Ubuntu