Resource exhaustion in Dovecot and OX Dovecot Pro - CVE-2026-40016

 

Resource exhaustion in Dovecot and OX Dovecot Pro - CVE-2026-40016

Published: May 19, 2026


Vulnerability identifier: #VU131866
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40016
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Sieve substring matching implementation when processing a malicious Sieve script. A remote user can upload a malicious Sieve script to cause a denial of service.

The script can be uploaded over the ManageSieve service or through local access, and the issue can bypass configured CPU time limits for Sieve by up to 130 times.


Affected software

Dovecot
OX Dovecot Pro
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
dovecot22-debuginfo
dovecot22-backend-pgsql-debuginfo
dovecot22-debugsource
dovecot22-devel
dovecot22-backend-sqlite
dovecot22
dovecot22-backend-sqlite-debuginfo
dovecot22-backend-mysql-debuginfo
dovecot22-backend-pgsql
dovecot22-backend-mysql
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot-help
dovecot-devel
dovecot-debugsource
dovecot-debuginfo
dovecot

How to mitigate CVE-2026-40016

Install security update from vendor's website.

Dovecot - update to 2.4.4
OX Dovecot Pro - update to 3.1.5
dovecot22-debuginfo - update to 2.2.31-19.43.1
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.43.1
dovecot22-debugsource - update to 2.2.31-19.43.1
dovecot22-devel - update to 2.2.31-19.43.1
dovecot22-backend-sqlite - update to 2.2.31-19.43.1
dovecot22 - update to 2.2.31-19.43.1
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.43.1
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.43.1
dovecot22-backend-pgsql - update to 2.2.31-19.43.1
dovecot22-backend-mysql - update to 2.2.31-19.43.1
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot-help - update to 2.3.20-5
dovecot-devel - update to 2.3.20-5
dovecot-debugsource - update to 2.3.20-5
dovecot-debuginfo - update to 2.3.20-5
dovecot - update to 2.3.20-5

External References

Related Security Bulletins