Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27858

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

A flaw was found in dovecot. An unauthenticated and remote attacker can send a crafted message that causes managesieve to allocate an excessive amount of memory, forcing managesieve-login to be unavailable by repeatedly crashing the process, resulting in a denial of service.

Отчет

This flaw allows an unauthenticated and remote attacker to cause a denial of service via a specially crafted message. Due to this reason, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, protect access to the managesieve protocol by configuring firewall rules to restrict access to the managesieve port and only allow connections from trusted IP addresses or networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dovecotWill not fix
Red Hat Enterprise Linux 10dovecotFixedRHSA-2026:1349804.05.2026
Red Hat Enterprise Linux 10dovecotFixedRHSA-2026:1914919.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportdovecotFixedRHSA-2026:1760214.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportdovecotFixedRHSA-2026:2656417.06.2026
Red Hat Enterprise Linux 8dovecotFixedRHSA-2026:1383005.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportdovecotFixedRHSA-2026:1945520.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OndovecotFixedRHSA-2026:1945520.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportdovecotFixedRHSA-2026:1945320.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicedovecotFixedRHSA-2026:1945320.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2452175dovecot: denial of service via crafted message before authentication

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
github
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость службы ManageSieve почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3