
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-52687 is a Denial of Service vulnerability in Open-Xchange (OX) Dovecot affecting its IMAP compression handling. An authenticated attacker can select a memory-intensive compression algorithm for IMAP connections and open multiple such connections, exhausting the process memory limit and terminating the imap-login process along with all connections it handles. Affected products include OX Dovecot Pro (versions 2.3.11 to <2.3.22.2, 3.0.0 to <3.0.7, and 3.1.0 to <3.1.6) and OX Dovecot CE (versions 2.3.11 to <2.4.5). The vulnerability was published on August 28, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Red Hat Bugzilla).
The root cause is uncontrolled resource consumption (CWE-400) and allocation of resources without limits or throttling (CWE-770) in Dovecot's IMAP compression subsystem. When an authenticated user negotiates a compression algorithm whose decompression state requires a disproportionately large amount of memory, the imap-login process accumulates memory across multiple such connections until the process memory limit is reached, causing it to terminate. Exploitation requires valid IMAP credentials (low privilege), is network-accessible, and requires no user interaction or complex conditions. No publicly available proof-of-concept exploit code is known (Github Advisory, Red Hat Bugzilla).
Successful exploitation causes the imap-login process to crash, terminating all IMAP connections handled by that process and resulting in a denial of service for all affected users. The impact is limited to availability — there is no confidentiality or integrity impact. Because a single imap-login process may handle many concurrent user sessions, even a small number of malicious connections (from a single authenticated attacker) can disrupt service for a broad user population (Github Advisory).
No publicly available exploits or proof-of-concept code are known for CVE-2026-52687, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.321%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
CAPABILITY command to confirm that IMAP COMPRESS extension is enabled and identify supported compression algorithms.COMPRESS command selecting a compression algorithm whose decompression state requires a large amount of memory.COMPRESS command usage from a single authenticated account in Dovecot IMAP logs; imap-login process crash entries or out-of-memory (OOM) kill events in system logs (e.g., /var/log/syslog, /var/log/messages, or journalctl).imap-login process; high memory consumption by imap-login processes visible via top or ps prior to crash.Upgrade to a patched version: OX Dovecot Pro 2.3.22.2, 3.0.7, or 3.1.6; OX Dovecot CE 2.4.5 or later. If immediate patching is not possible, disable IMAP compression entirely as a temporary workaround. Alternatively, limit the number of connections handled by a single imap-login process to reduce the blast radius, though this may have a performance impact. Patches and advisories are available from Open-Xchange (Github Advisory, Red Hat Bugzilla).
The vulnerability was disclosed via the oss-security mailing list and full-disclosure list, and received coverage from Linux distribution security teams including SUSE, openSUSE, and Red Hat. SUSE issued a security update (SUSE-SU-2026:3919-1) for dovecot22, and openSUSE published a corresponding advisory. The vulnerability was also picked up by security aggregators such as Tenable (Nessus plugin 341534), Qualys, INCIBE-CERT, and AusCERT. Community reaction has been measured, consistent with a medium-severity, authenticated-only DoS with no public exploit.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
dovecot
devel
dovecot
focal (esm-infra)
dovecot
jammy
dovecot
noble
dovecot
resolute
dovecot
trusty (esm-infra-legacy)
dovecot
xenial (esm-infra-legacy)
dovecot
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."