Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40203

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in dovecot where, when IMAP compression is enabled, the system reuses the same compression state across responses within a session. This allows a remote attacker, who can send mail to a user and monitor the sizes of their IMAP traffic, to potentially deduce the content of small messages. By observing response sizes, an attacker could confirm if a secret message body matches a guessed text, leading to information disclosure.

Меры по смягчению последствий

To mitigate this issue, disable IMAP compression in the Dovecot configuration. This typically involves setting imap_compression = no in the relevant Dovecot configuration file. After making this change, restart the Dovecot service for the mitigation to take effect. Restarting the service may temporarily interrupt IMAP access for users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-205
https://bugzilla.redhat.com/show_bug.cgi?id=2525535dovecot: Dovecot: Information disclosure via IMAP compression side-channel

EPSS

Процентиль: 12%
0.00219
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
16 дней назад

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.7
nvd
16 дней назад

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.7
debian
16 дней назад

When IMAP compression is enabled, the same compression state is reused ...

CVSS3: 3.7
github
16 дней назад

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
11 дней назад

Security update for dovecot22

EPSS

Процентиль: 12%
0.00219
Низкий

3.7 Low

CVSS3