An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade dovecot-pigeonholeUpgrade dovecot-develUpgrade dovecot-pgsqlUpgrade dovecotUpgrade dovecot-mysql | Jul 23, 2026 | Jul 20, 2026 |
| Alpine Linux | — | Upgrade dovecot | Aug 3, 2026 | May 12, 2026 |
| Debian | — | Upgrade dovecot | Jun 1, 2026 | Jun 1, 2026 |
| Redhat_linux | — | Upgrade dovecot-debugsourceUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecotUpgrade dovecot-mysqlUpgrade dovecot-debuginfoUpgrade dovecot-mysql-debuginfoUpgrade dovecot-pigeonholeUpgrade dovecot-pigeonhole-debuginfoNo solution exists | Jul 17, 2026 | May 12, 2026 |
| Rocky_linux | — | Upgrade dovecot-debuginfoUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-pigeonholeUpgrade dovecotUpgrade dovecot-mysql-debuginfoUpgrade dovecot-debugsourceUpgrade dovecot-mysqlUpgrade dovecot-pigeonhole-debuginfoUpgrade dovecot-pgsqlUpgrade dovecot-devel | Jul 27, 2026 | Jul 22, 2026 |
| Ubuntu | — | Upgrade dovecot-core | Jun 2, 2026 | Jun 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub