PT-2026-40030 · Dovecot · Dovecot

Published

2026-05-12

·

Updated

2026-06-02

·

CVE-2026-42006

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.4-1.1
Description An attacker can cause uncontrolled memory usage via excessive bracing over IMAP. A previous fix was incomplete as it only blocked closing braces, allowing the memory limit to be bypassed using open braces. This can lead to memory consumption reaching the configured limit.
Recommendations Update to version 2.4.4-1.1. Configure vsz limit for the imap process to a low value.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-42006
OPENSUSE-SU-2026:10766-1
USN-8365-1

Affected Products

Dovecot