CVE 4.3 MEDIUM

CVE-2026-42006_CVE-2026-42006

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Description

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

Basic Information

ID CVE-2026-42006
Source OX
Published May 12, 2026 at 13:28
Modified May 12, 2026 at 13:39

Affected Product

Vendor Open-Xchange GmbH
Product OX Dovecot Pro
Affected Versions Open-Xchange GmbH OX Dovecot Pro 0
Open-Xchange GmbH OX Dovecot Pro 0
Open-Xchange GmbH OX Dovecot Pro 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.