Alpine: multiple dovecot packages: security update to 2.4.4-r0

critical Tenable Self-Hosted Container Security Plugin ID 445579

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- When safe filter is used with variable expansion, all following pipelines on the same string are
incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP
injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly
available exploits are known. (CVE-2026-27851)

- Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel
binding. This requires that the attacker is able to position itself between Dovecot and the client
connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM
proxy. Install fixed version. No publicly available exploits are known. (CVE-2026-33603)

- Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured
CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server
performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or
alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly
available exploits are known. (CVE-2026-40016)

- Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even
if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to
being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No
publicly available exploits are known. (CVE-2026-40020)

- An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in
CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left
open. In particular, the fix was for closing braces, but you could still use open braces to bypass the
limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install
fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are
known. (CVE-2026-42006)

Solution

Update the dovecot library and its related packages to version 2.4.4-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-27851

https://security.alpinelinux.org/vuln/CVE-2026-33603

https://security.alpinelinux.org/vuln/CVE-2026-40016

https://security.alpinelinux.org/vuln/CVE-2026-40020

https://security.alpinelinux.org/vuln/CVE-2026-42006

Plugin Details

Severity: Critical

ID: 445579

Version: Revision 1.1

Type: Local

Published: 8/1/2026

Updated: 8/1/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.61

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-27851

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-27851, CVE-2026-33603, CVE-2026-40016, CVE-2026-40020, CVE-2026-42006