Количество 19
Количество 19
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ...
GHSA-j26c-8p6m-gpfj
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.
BDU:2026-10388
Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260707-73-0042
Уязвимость dovecot
RLSA-2026:19364
Important: dovecot security update
RLSA-2026:19149
Important: dovecot security update
RLSA-2026:13857
Important: dovecot security update
RLSA-2026:13830
Important: dovecot security update
RLSA-2026:13498
Important: dovecot security update
ELSA-2026-19364
ELSA-2026-19364: dovecot security update (IMPORTANT)
ELSA-2026-19149
ELSA-2026-19149: dovecot security update (IMPORTANT)
ELSA-2026-13857
ELSA-2026-13857: dovecot security update (IMPORTANT)
ELSA-2026-13830
ELSA-2026-13830: dovecot security update (IMPORTANT)
ELSA-2026-13498
ELSA-2026-13498: dovecot security update (IMPORTANT)
SUSE-SU-2026:1641-1
Security update for dovecot22
openSUSE-SU-2026:20554-1
Security update for dovecot24
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known. | CVSS3: 4.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known. | CVSS3: 4.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ... | CVSS3: 4.3 | 1% Низкий | 4 месяца назад | |
GHSA-j26c-8p6m-gpfj Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known. | CVSS3: 4.3 | 1% Низкий | 4 месяца назад | |
BDU:2026-10388 Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260707-73-0042 Уязвимость dovecot | CVSS3: 7.5 | 1% Низкий | 25 дней назад | |
RLSA-2026:19364 Important: dovecot security update | 2 месяца назад | |||
RLSA-2026:19149 Important: dovecot security update | 2 месяца назад | |||
RLSA-2026:13857 Important: dovecot security update | 3 месяца назад | |||
RLSA-2026:13830 Important: dovecot security update | 3 месяца назад | |||
RLSA-2026:13498 Important: dovecot security update | 3 месяца назад | |||
ELSA-2026-19364 ELSA-2026-19364: dovecot security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-19149 ELSA-2026-19149: dovecot security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-13857 ELSA-2026-13857: dovecot security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-13830 ELSA-2026-13830: dovecot security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-13498 ELSA-2026-13498: dovecot security update (IMPORTANT) | 3 месяца назад | |||
SUSE-SU-2026:1641-1 Security update for dovecot22 | 3 месяца назад | |||
openSUSE-SU-2026:20554-1 Security update for dovecot24 | 4 месяца назад |
Уязвимостей на страницу