
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27857 is an uncontrolled resource consumption (denial-of-service) vulnerability in Dovecot IMAP server affecting all versions before 2.4.3 (community edition) and OX Dovecot Pro before 2.3.22.1, 3.0.5, and 3.1.4. The flaw was disclosed on March 27, 2026, by Open-Xchange (OX). It carries a CVSS v3.1 base score of 7.5 (High) per NVD, though the ENISA EUVD assigns a lower score of 4.3 based on a different vector (OX Advisory, ENISA EUVD).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and stems from how Dovecot processes IMAP NOOP commands with deeply nested parentheses. Sending a NOOP (((...))) command with approximately 4,000 open/close parenthesis pairs causes roughly 1 MB of extra memory allocation per connection. An attacker can withhold the command-terminating line feed (LF) to keep this memory allocated indefinitely, then open 1,000 simultaneous connections from a single IP to consume approximately 1 GB of memory — sufficient to reach the process's VSZ limit and kill it along with all proxied connections. No authentication is required to exploit this condition (OX Advisory, oss-sec).
Successful exploitation results in a complete denial of service for the affected Dovecot process, terminating all active proxied IMAP connections and making the mail server unavailable to legitimate users. There is no confidentiality or integrity impact — the vulnerability is purely an availability issue. Because a single attacker IP can trigger the condition with 1,000 connections, the attack is low-cost and does not require distributed infrastructure (OX Advisory, ENISA EUVD).
NOOP command with approximately 4,000 nested parenthesis pairs (e.g., A001 NOOP (((...)))) — this triggers ~1 MB of extra memory allocation per connection.NOOP commands with unusually long argument strings in IMAP access logs.dmesg, syslog) showing OOM-killer activity or process killed due to memory exhaustion.The vendor states there is no configuration-based workaround — installing a fixed version is the only remediation. Affected users should upgrade to Dovecot community edition 2.4.3 or later, or OX Dovecot Pro 2.3.22.1, 3.0.5, or 3.1.4 as appropriate. Patches have also been distributed through major Linux distributions including Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197-1, DLA-4556-1, DLA-4617-1), Red Hat (RHSA-2026:13498, RHSA-2026:13830, RHSA-2026:13857, and others), Amazon Linux 2023 (ALAS2023-2026-1570), Amazon Linux 2 (ALAS2-2026-3252), openSUSE, Fedora, and AlmaLinux (OX Advisory, Ubuntu Advisory, Red Hat Advisory).
The vulnerability was disclosed via the oss-sec mailing list and full-disclosure list, generating standard community awareness without notable controversy. Multiple Linux distribution security teams responded promptly with patches within days to weeks of disclosure. No significant researcher commentary or media coverage beyond routine vulnerability tracking has been observed (oss-sec, Full Disclosure).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."