CVE-2026-27859
Dovecot vulnerability analysis and mitigation

Overview

CVE-2026-27859 is an uncontrolled resource consumption vulnerability in Dovecot's LMTP (Local Mail Transfer Protocol) component that allows unauthenticated remote attackers to cause a denial of service by sending mail messages containing an excessive number of RFC 2231 MIME parameters. The vulnerability was published on March 27, 2026, and affects Dovecot versions prior to 2.4.3, Open-Xchange Dovecot Pro versions prior to 3.0.5, and Open-Xchange Dovecot Pro 3.1.x versions prior to 3.1.4. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, OX Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). When Dovecot's LMTP mail delivery process parses a specially crafted email containing an excessive number of RFC 2231 MIME parameters, it fails to impose adequate limits on processing time, resulting in unbounded CPU consumption. The attack requires no authentication, no user interaction, and no special privileges — an attacker simply needs to deliver a malformed message to the target mail server over the network. The fixed versions address this by enforcing limits on the number of RFC 2231 MIME parameters processed (Feedly, OX Advisory).

Impact

Successful exploitation causes the Dovecot LMTP mail delivery process to consume large amounts of CPU time, resulting in a denial of service condition that can degrade or halt mail delivery on the affected server. Because the attack is unauthenticated and requires only the ability to send email to the target, it is accessible to any remote attacker. There is no impact on confidentiality or integrity; the vulnerability is limited to availability (Feedly).

Exploitation steps

  1. Reconnaissance: Identify mail servers running vulnerable versions of Dovecot (prior to 2.4.3) or Open-Xchange Dovecot Pro (prior to 3.0.5 or 3.1.4) using banner grabbing or service enumeration tools such as nmap.
  2. Craft malicious email: Construct an email message containing an excessive number of RFC 2231 MIME parameters in message headers or body parts (e.g., hundreds or thousands of Content-Type or Content-Disposition parameters using RFC 2231 encoding).
  3. Deliver the message: Send the crafted email to the target mail server via SMTP so that it is routed through the vulnerable Dovecot LMTP delivery process.
  4. Trigger CPU exhaustion: The LMTP process attempts to parse all RFC 2231 parameters without limit, consuming excessive CPU resources and causing denial of service for mail delivery on the affected server (Feedly, OX Advisory).

Indicators of compromise

  • Logs: Dovecot LMTP logs showing unusually long processing times or timeouts for individual message deliveries; repeated log entries for the same sender or message with MIME parsing activity.
  • Process: Sustained high CPU utilization by the dovecot or lmtp process without a corresponding spike in legitimate mail volume; top or ps output showing LMTP worker processes consuming near 100% CPU.
  • Network: Unusual volume of inbound SMTP connections delivering messages with abnormally large or complex MIME headers from a single source IP or range.

Mitigation and workarounds

Organizations should upgrade to Dovecot 2.4.3 or later, Open-Xchange Dovecot Pro 3.0.5 or later, or Open-Xchange Dovecot Pro 3.1.4 or later, where processing of RFC 2231 MIME parameters is limited. As an interim workaround, administrators can configure MTA-level (e.g., Postfix, Exim) policies to reject or strip messages containing an excessive number of MIME parameters before they reach Dovecot's LMTP component. Ubuntu security notice USN-8136-1 and Debian LTS DLA-4556-1 have also issued updated packages for their respective distributions (OX Advisory, Ubuntu Advisory, Debian LTS).

Community reactions

The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, generating routine community attention typical of moderate-severity mail server vulnerabilities. Linux distribution vendors including Ubuntu, Debian, and openSUSE issued security advisories and updated packages in the weeks following disclosure. No notable researcher commentary or significant social media discussion beyond standard CVE tracking has been observed (oss-sec, Full Disclosure, Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27851CRITICAL9.1
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026
CVE-2026-40016MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot-pigeonhole-debuginfo
NoYesMay 12, 2026
CVE-2026-33603MEDIUM5.3
  • Dovecot logoDovecot
  • dovecot24
NoYesMay 12, 2026
CVE-2026-42006MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot-mysql-debuginfo
NoYesMay 12, 2026
CVE-2026-40020MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management