
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33603 is a SCRAM TLS channel binding bypass vulnerability in Dovecot, an open-source IMAP and POP3 server. An attacker positioned on the adjacent network between Dovecot and a client can use a specially crafted base64 exchange to fake SCRAM TLS channel binding, enabling a man-in-the-middle (MITM) proxy attack. The vulnerability affects Dovecot versions prior to 2.4.4 (community edition) and OX Dovecot Pro versions prior to 3.1.5. It was published on May 12, 2026, with a CVSS v3.1 base score of 6.8 (Medium) per the GitHub Advisory Database, or 5.3 (Medium) per NVD (GitHub Advisory, OX Advisory).
The vulnerability is classified as CWE-99 (Improper Control of Resource Identifiers / Resource Injection), arising from insufficient validation of base64-encoded data during the SCRAM (Salted Challenge Response Authentication Mechanism) authentication handshake. An attacker who can position themselves between the Dovecot server and a connecting client can manipulate the SCRAM authentication exchange to bypass TLS channel binding verification — a security mechanism designed to cryptographically bind authentication to the underlying TLS session. This allows the attacker to impersonate a legitimate TLS endpoint and establish a MITM proxy without detection. Exploitation requires adjacent network access and high attack complexity, as the attacker must be able to intercept and modify traffic in real time (GitHub Advisory, OX Advisory).
Successful exploitation allows an unauthenticated adjacent-network attacker to eavesdrop on and intercept all communications between Dovecot and its clients by acting as a MITM proxy. This results in a high confidentiality impact (exposure of email content, credentials, and session data) and, per the GitHub Advisory scoring, a high integrity impact (potential for message tampering). Availability is not affected. The attack scope is limited to the connection between Dovecot and the targeted client, but could expose sensitive mail server communications including authentication credentials (GitHub Advisory, OX Advisory).
auth-verbose=yes output).Upgrade Dovecot to version 2.4.4 or later (community edition), or OX Dovecot Pro to version 3.1.5 or later, as these releases contain the fix (OX Advisory). Distribution-specific patches have been released for openSUSE, Ubuntu (USN-8365-1), Debian, and Fedora. As a workaround, implement network segmentation to prevent attackers from positioning themselves between mail servers and clients, and monitor for suspicious SCRAM authentication patterns. Consider enforcing strict network access controls on the mail server segment to reduce the risk of adjacent-network attacks.
The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure in May 2026, prompting patch releases from major Linux distributions including Ubuntu, Debian, Fedora, and openSUSE within days of disclosure (openSUSE Announce, Ubuntu Advisory, Debian LTS). Community reaction has been measured given the moderate severity and high exploitation complexity. No notable threat actor attribution or significant social media discussion has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."