Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27858

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

A flaw was found in dovecot. An unauthenticated and remote attacker can send a crafted message that causes managesieve to allocate an excessive amount of memory, forcing managesieve-login to be unavailable by repeatedly crashing the process, resulting in a denial of service.

Отчет

This flaw allows an unauthenticated and remote attacker to cause a denial of service via a specially crafted message. Due to this reason, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, protect access to the managesieve protocol by configuring firewall rules to restrict access to the managesieve port and only allow connections from trusted IP addresses or networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotAffected
Red Hat Enterprise Linux 6dovecotAffected
Red Hat Enterprise Linux 7dovecotAffected
Red Hat Enterprise Linux 8dovecotAffected
Red Hat Enterprise Linux 9dovecotAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2452175dovecot: denial of service via crafted message before authentication

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
5 дней назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
5 дней назад

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
github
5 дней назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3