Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40016

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.

A flaw was found in Dovecot. A remote or local attacker could upload a malicious Sieve script through the ManageSieve service, or locally, to bypass configured CPU time limits for Sieve scripts. This allows the attacker to consume excessive server resources, leading to a degradation of server performance and a Denial of Service (DoS).

Меры по смягчению последствий

To mitigate this issue, restrict access to the ManageSieve service to trusted users or networks. If the ManageSieve service is not essential, consider disabling it. Additionally, ensure that local user access to Sieve script directories is appropriately controlled. Any changes to Dovecot configuration may require a service reload or restart, potentially causing a brief interruption to mail services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2476470dovecot: Dovecot: Denial of Service due to Sieve script CPU limit bypass

EPSS

Процентиль: 26%
0.00338
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.

CVSS3: 5.3
nvd
3 месяца назад

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.

CVSS3: 5.3
debian
3 месяца назад

Attacker can upload a malicious Sieve script over ManageSieve service ...

CVSS3: 5.3
github
3 месяца назад

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость службы ManageSieve почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00338
Низкий

6.5 Medium

CVSS3