Resource exhaustion in Dovecot and OX Dovecot Pro - CVE-2026-40016
Published: May 19, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Sieve substring matching implementation when processing a malicious Sieve script. A remote user can upload a malicious Sieve script to cause a denial of service.
The script can be uploaded over the ManageSieve service or through local access, and the issue can bypass configured CPU time limits for Sieve by up to 130 times.
Affected software
OX Dovecot Pro
Debian Linux
openEuler
Ubuntu
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot
dovecot-debuginfo
dovecot-debugsource
dovecot-devel
dovecot-help
How to mitigate CVE-2026-40016
OX Dovecot Pro - update to 3.1.5
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot - update to 2.3.20-5
dovecot-debuginfo - update to 2.3.20-5
dovecot-debugsource - update to 2.3.20-5
dovecot-devel - update to 2.3.20-5
dovecot-help - update to 2.3.20-5