Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33607

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.

A flaw was found in Dovecot. An authenticated attacker can exploit a vulnerability in the IMAP LIST command to consume excessive CPU resources. This can lead to a degradation of service or a complete denial of service (DoS) for the IMAP server, impacting the availability of email services.

Меры по смягчению последствий

To mitigate this issue, restrict access to the Dovecot IMAP service to trusted networks or localhost using firewall rules or Dovecot's configuration. Additionally, implement system monitoring for abnormal CPU utilization by Dovecot processes to detect and respond to potential exploitation attempts. If network configuration changes are applied, a restart of the Dovecot service may be required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2525552dovecot: Dovecot: Denial of Service via IMAP LIST command

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
17 дней назад

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.

CVSS3: 4.3
nvd
17 дней назад

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.

CVSS3: 4.3
debian
17 дней назад

An attacker that has valid credentials can use IMAP LIST command to co ...

CVSS3: 4.3
github
17 дней назад

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.

suse-cvrf
12 дней назад

Security update for dovecot22

4.3 Medium

CVSS3