
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27859 is an uncontrolled resource consumption vulnerability in Dovecot's LMTP (Local Mail Transfer Protocol) component that allows unauthenticated remote attackers to cause a denial of service by sending mail messages containing an excessive number of RFC 2231 MIME parameters. The vulnerability was published on March 27, 2026, and affects Dovecot versions prior to 2.4.3, Open-Xchange Dovecot Pro versions prior to 3.0.5, and Open-Xchange Dovecot Pro 3.1.x versions prior to 3.1.4. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, OX Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). When Dovecot's LMTP mail delivery process parses a specially crafted email containing an excessive number of RFC 2231 MIME parameters, it fails to impose adequate limits on processing time, resulting in unbounded CPU consumption. The attack requires no authentication, no user interaction, and no special privileges — an attacker simply needs to deliver a malformed message to the target mail server over the network. The fixed versions address this by enforcing limits on the number of RFC 2231 MIME parameters processed (Feedly, OX Advisory).
Successful exploitation causes the Dovecot LMTP mail delivery process to consume large amounts of CPU time, resulting in a denial of service condition that can degrade or halt mail delivery on the affected server. Because the attack is unauthenticated and requires only the ability to send email to the target, it is accessible to any remote attacker. There is no impact on confidentiality or integrity; the vulnerability is limited to availability (Feedly).
nmap.Content-Type or Content-Disposition parameters using RFC 2231 encoding).dovecot or lmtp process without a corresponding spike in legitimate mail volume; top or ps output showing LMTP worker processes consuming near 100% CPU.Organizations should upgrade to Dovecot 2.4.3 or later, Open-Xchange Dovecot Pro 3.0.5 or later, or Open-Xchange Dovecot Pro 3.1.4 or later, where processing of RFC 2231 MIME parameters is limited. As an interim workaround, administrators can configure MTA-level (e.g., Postfix, Exim) policies to reject or strip messages containing an excessive number of MIME parameters before they reach Dovecot's LMTP component. Ubuntu security notice USN-8136-1 and Debian LTS DLA-4556-1 have also issued updated packages for their respective distributions (OX Advisory, Ubuntu Advisory, Debian LTS).
The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, generating routine community attention typical of moderate-severity mail server vulnerabilities. Linux distribution vendors including Ubuntu, Debian, and openSUSE issued security advisories and updated packages in the weeks following disclosure. No notable researcher commentary or significant social media discussion beyond standard CVE tracking has been observed (oss-sec, Full Disclosure, Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."