Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40014

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot. A remote attacker, by sending a specially crafted email message header to a user, can cause the Internet Message Access Protocol (IMAP) THREAD command to consume excessive CPU resources. When a mail client processes this message, it can lead to degradation or a denial of service for the IMAP server.

Меры по смягчению последствий

To mitigate this issue, administrators should monitor Dovecot processes for abnormal CPU usage. If high CPU consumption is observed, identify and terminate the offending Dovecot process. Subsequently, remove the malicious email from the affected mailbox to prevent re-triggering the vulnerability. Restarting the Dovecot service may be required after process termination, which could temporarily impact mail service availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2525543dovecot: Dovecot: Denial of Service via crafted IMAP THREAD command

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 6.5
nvd
16 дней назад

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 6.5
debian
16 дней назад

An attacker that can send mail to a user can craft a message header th ...

CVSS3: 6.5
github
16 дней назад

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
11 дней назад

Security update for dovecot22

6.5 Medium

CVSS3