An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecot-pigeonholeUpgrade dovecotUpgrade dovecot-mysql | Jul 23, 2026 | Jul 20, 2026 |
| Alpine Linux | — | Upgrade dovecot | Aug 3, 2026 | May 12, 2026 |
| Debian | — | Upgrade dovecot | Jun 1, 2026 | Jun 1, 2026 |
| Redhat_linux | — | Upgrade dovecot-develUpgrade dovecot-debugsourceUpgrade dovecotUpgrade dovecot-pgsqlUpgrade dovecot-mysqlUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-mysql-debuginfoUpgrade dovecot-debuginfoNo solution existsUpgrade dovecot-pigeonholeUpgrade dovecot-pigeonhole-debuginfo | Jul 17, 2026 | May 12, 2026 |
| Rocky_linux | — | Upgrade dovecot-develUpgrade dovecot-debugsourceUpgrade dovecot-pgsqlUpgrade dovecot-pigeonhole-debuginfoUpgrade dovecot-mysql-debuginfoUpgrade dovecot-mysqlUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-debuginfoUpgrade dovecot-pigeonholeUpgrade dovecot | Jul 27, 2026 | Jul 22, 2026 |
| Ubuntu | — | Upgrade dovecot-core | Jun 2, 2026 | Jun 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub