An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Aug 31, 2026 | Aug 28, 2026 |
| Redhat_linux | — | Upgrade dovecot-debuginfoNo solution existsUpgrade dovecot-debugsourceUpgrade dovecot-pigeonholeUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-mysqlUpgrade dovecot-pgsqlUpgrade dovecot-mysql-debuginfoUpgrade dovecotUpgrade dovecot-develUpgrade dovecot-pigeonhole-debuginfo | Sep 2, 2026 | Aug 28, 2026 |
| Rocky_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-develUpgrade dovecot-pigeonholeUpgrade dovecot-debugsourceUpgrade dovecot-mysqlUpgrade dovecot-debuginfoUpgrade dovecot-pigeonhole-debuginfoUpgrade dovecotUpgrade dovecot-mysql-debuginfo | Oct 8, 2026 | Oct 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub