Improper Control of Resource Identifiers ('Resource Injection') in Dovecot and OX Dovecot Pro - CVE-2026-33603
Published: May 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to eavesdrop communications between Dovecot and a client.
The vulnerability exists due to improper control of resource identifiers in login when processing a specially crafted base64 exchange between Dovecot and the client. A remote attacker can send a specially crafted base64 exchange to eavesdrop communications between Dovecot and a client.
Exploitation requires the ability to position between Dovecot and the client connection and can be used to fake SCRAM TLS channel binding.
Affected software
OX Dovecot Pro
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
Fedora
dovecot22-backend-mysql-debuginfo
dovecot22-backend-sqlite-debuginfo
dovecot22-debugsource
dovecot22-backend-pgsql-debuginfo
dovecot22-backend-mysql
dovecot22-backend-pgsql
dovecot22
dovecot22-devel
dovecot22-debuginfo
dovecot22-backend-sqlite
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot-devel
dovecot-help
dovecot-debugsource
dovecot-debuginfo
dovecot
How to mitigate CVE-2026-33603
OX Dovecot Pro - update to 3.1.5
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.37.2
dovecot22-debugsource - update to 2.2.31-19.37.2
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-mysql - update to 2.2.31-19.37.2
dovecot22-backend-pgsql - update to 2.2.31-19.37.2
dovecot22 - update to 2.2.31-19.37.2
dovecot22-devel - update to 2.2.31-19.37.2
dovecot22-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite - update to 2.2.31-19.37.2
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot-devel - update to 2.3.20-5
dovecot-help - update to 2.3.20-5
dovecot-debugsource - update to 2.3.20-5
dovecot-debuginfo - update to 2.3.20-5
dovecot - update to 2.3.20-5
dovecot - addressed in versions 2.4.4-1.fc43, 2.4.4-1.fc44