Resource exhaustion in Dovecot and OX Dovecot Pro - CVE-2026-27859
Published: April 1, 2026
Dovecot
OX Dovecot Pro
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in MIME parameter parsing when processing message headers. A remote attacker can send a specially crafted email message with excessive RFC 2231 MIME parameters to cause a denial of service of the LMTP mail delivery process.