Improper Control of Resource Identifiers ('Resource Injection') in Dovecot and OX Dovecot Pro - CVE-2026-33603

 

Improper Control of Resource Identifiers ('Resource Injection') in Dovecot and OX Dovecot Pro - CVE-2026-33603

Published: May 19, 2026


Vulnerability identifier: #VU131867
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33603
CWE-ID: CWE-99
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to eavesdrop communications between Dovecot and a client.

The vulnerability exists due to improper control of resource identifiers in login when processing a specially crafted base64 exchange between Dovecot and the client. A remote attacker can send a specially crafted base64 exchange to eavesdrop communications between Dovecot and a client.

Exploitation requires the ability to position between Dovecot and the client connection and can be used to fake SCRAM TLS channel binding.


Affected software

Dovecot
OX Dovecot Pro
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
Fedora
dovecot22-backend-mysql-debuginfo
dovecot22-backend-sqlite-debuginfo
dovecot22-debugsource
dovecot22-backend-pgsql-debuginfo
dovecot22-backend-mysql
dovecot22-backend-pgsql
dovecot22
dovecot22-devel
dovecot22-debuginfo
dovecot22-backend-sqlite
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot-devel
dovecot-help
dovecot-debugsource
dovecot-debuginfo
dovecot

How to mitigate CVE-2026-33603

Install security update from vendor's website.

Dovecot - update to 2.4.4
OX Dovecot Pro - update to 3.1.5
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.37.2
dovecot22-debugsource - update to 2.2.31-19.37.2
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-mysql - update to 2.2.31-19.37.2
dovecot22-backend-pgsql - update to 2.2.31-19.37.2
dovecot22 - update to 2.2.31-19.37.2
dovecot22-devel - update to 2.2.31-19.37.2
dovecot22-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite - update to 2.2.31-19.37.2
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot-devel - update to 2.3.20-5
dovecot-help - update to 2.3.20-5
dovecot-debugsource - update to 2.3.20-5
dovecot-debuginfo - update to 2.3.20-5
dovecot - update to 2.3.20-5
dovecot - addressed in versions 2.4.4-1.fc43, 2.4.4-1.fc44

External References

Related Security Bulletins