Improper Control of Resource Identifiers ('Resource Injection') in Dovecot and OX Dovecot Pro - CVE-2026-33603
Published: May 19, 2026
Dovecot
OX Dovecot Pro
Detailed vulnerability description
The vulnerability allows a remote attacker to eavesdrop communications between Dovecot and a client.
The vulnerability exists due to improper control of resource identifiers in login when processing a specially crafted base64 exchange between Dovecot and the client. A remote attacker can send a specially crafted base64 exchange to eavesdrop communications between Dovecot and a client.
Exploitation requires the ability to position between Dovecot and the client connection and can be used to fake SCRAM TLS channel binding.