Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52687

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in dovecot. A remote attacker with valid credentials can exploit this vulnerability by selecting a compression algorithm for the IMAP connection that requires a large amount of memory for decompression. By opening several such connections, the attacker can exhaust the process's memory limit, leading to the termination of the process and all its connections. This can cause degradation or a complete denial of service for IMAP.

Меры по смягчению последствий

To mitigate this vulnerability, disable IMAP compression in the Dovecot configuration. This can be achieved by ensuring that zlib or other compression plugins are not loaded for IMAP services. For example, remove zlib from the mail_plugins setting in dovecot.conf or a relevant configuration file. A restart of the Dovecot service is required for the changes to take effect. Disabling compression may result in increased network bandwidth usage for IMAP connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2525579dovecot: dovecot: Denial of Service via IMAP compression memory exhaustion

EPSS

Процентиль: 25%
0.00321
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
10 дней назад

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 6.5
nvd
10 дней назад

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 6.5
debian
10 дней назад

An attacker that has valid credentials can select a compression algori ...

CVSS3: 6.5
github
10 дней назад

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
6 дней назад

Security update for dovecot24

EPSS

Процентиль: 25%
0.00321
Низкий

6.5 Medium

CVSS3