Description
There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:
- An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a
use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the
delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery,
which can crash the delivery process and may allow execution of arbitrary code in the context of that
process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available
exploits are known. (CVE-2026-42007)
- An attacker that can send mail to a user can craft a message whose headers contain a very large number of
email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed.
The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and
terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No
publicly available exploits are known. (CVE-2026-27852)
- When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll()
panic caused by file descriptor handling issues. If running in high-security mode (default for community
releases), only the new submission connection gets terminated. If running in high-performance mode
(default for Pro releases), all connections handled by the submission-login process will be terminated.
The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent.
If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen,
because the crash can only happen at AUTH stage. Limit the number of connections handled by single
submission-login process. This has a performance impact though. Update to non-vulnerable version. No
publicly available exploits are known. (CVE-2026-33263)
- An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission
relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents
message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed
the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP
commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and
CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in
message data. Update to non-vulnerable version. No publicly available exploits are known. (CVE-2026-33604)
- An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command
before authenticating. If running in high-security mode (default for community releases), only the
attacker's own connection is terminated. If running in high-performance mode (default for Pro releases),
all connections handled by the same managesieve-login process are terminated. Repeating the attack can
cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to
trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
(CVE-2026-33605)
Solution
Update the dovecot library and its related packages to version 2.4.5-r0 or later.
Plugin Details
Supported Sensors: Agentless Assessment
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 8/28/2026
Reference Information
CVE: CVE-2026-27852, CVE-2026-33263, CVE-2026-33604, CVE-2026-33605, CVE-2026-33606, CVE-2026-33607, CVE-2026-40014, CVE-2026-40015, CVE-2026-40017, CVE-2026-40019, CVE-2026-40203, CVE-2026-40205, CVE-2026-42007, CVE-2026-42391, CVE-2026-42392, CVE-2026-42393, CVE-2026-42395, CVE-2026-52681, CVE-2026-52687, CVE-2026-73208, CVE-2026-73209