CVE-2026-52687
Dovecot vulnerability analysis and mitigation

Overview

CVE-2026-52687 is a Denial of Service vulnerability in Open-Xchange (OX) Dovecot affecting its IMAP compression handling. An authenticated attacker can select a memory-intensive compression algorithm for IMAP connections and open multiple such connections, exhausting the process memory limit and terminating the imap-login process along with all connections it handles. Affected products include OX Dovecot Pro (versions 2.3.11 to <2.3.22.2, 3.0.0 to <3.0.7, and 3.1.0 to <3.1.6) and OX Dovecot CE (versions 2.3.11 to <2.4.5). The vulnerability was published on August 28, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) and allocation of resources without limits or throttling (CWE-770) in Dovecot's IMAP compression subsystem. When an authenticated user negotiates a compression algorithm whose decompression state requires a disproportionately large amount of memory, the imap-login process accumulates memory across multiple such connections until the process memory limit is reached, causing it to terminate. Exploitation requires valid IMAP credentials (low privilege), is network-accessible, and requires no user interaction or complex conditions. No publicly available proof-of-concept exploit code is known (Github Advisory, Red Hat Bugzilla).

Impact

Successful exploitation causes the imap-login process to crash, terminating all IMAP connections handled by that process and resulting in a denial of service for all affected users. The impact is limited to availability — there is no confidentiality or integrity impact. Because a single imap-login process may handle many concurrent user sessions, even a small number of malicious connections (from a single authenticated attacker) can disrupt service for a broad user population (Github Advisory).

Exploitability

No publicly available exploits or proof-of-concept code are known for CVE-2026-52687, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.321%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Obtain valid credentials: Acquire a legitimate IMAP account on a target Dovecot server running a vulnerable version (OX Dovecot Pro <2.3.22.2, <3.0.7, or <3.1.6; OX Dovecot CE <2.4.5).
  2. Identify compression support: Connect to the IMAP server and issue a CAPABILITY command to confirm that IMAP COMPRESS extension is enabled and identify supported compression algorithms.
  3. Negotiate memory-intensive compression: For each connection, authenticate and issue the IMAP COMPRESS command selecting a compression algorithm whose decompression state requires a large amount of memory.
  4. Open multiple connections: Repeat step 3 across several simultaneous connections. Each connection's decompression state accumulates memory within the imap-login process.
  5. Exhaust process memory: With only a few such connections, the imap-login process reaches its memory limit, causing it to terminate and dropping all IMAP sessions it was handling, resulting in denial of service for all users on that process (Github Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Repeated IMAP COMPRESS command usage from a single authenticated account in Dovecot IMAP logs; imap-login process crash entries or out-of-memory (OOM) kill events in system logs (e.g., /var/log/syslog, /var/log/messages, or journalctl).
  • Process: Unexpected termination of the imap-login process; high memory consumption by imap-login processes visible via top or ps prior to crash.
  • Network: Multiple simultaneous IMAP connections from the same source IP or authenticated user, particularly with compression negotiation; sudden disconnection of all IMAP sessions served by a single process.

Mitigation and workarounds

Upgrade to a patched version: OX Dovecot Pro 2.3.22.2, 3.0.7, or 3.1.6; OX Dovecot CE 2.4.5 or later. If immediate patching is not possible, disable IMAP compression entirely as a temporary workaround. Alternatively, limit the number of connections handled by a single imap-login process to reduce the blast radius, though this may have a performance impact. Patches and advisories are available from Open-Xchange (Github Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was disclosed via the oss-security mailing list and full-disclosure list, and received coverage from Linux distribution security teams including SUSE, openSUSE, and Red Hat. SUSE issued a security update (SUSE-SU-2026:3919-1) for dovecot22, and openSUSE published a corresponding advisory. The vulnerability was also picked up by security aggregators such as Tenable (Nessus plugin 341534), Qualys, INCIBE-CERT, and AusCERT. Community reaction has been measured, consistent with a medium-severity, authenticated-only DoS with no public exploit.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

dovecot

Affected

sid

dovecot: 1:2.4.5+dfsg1-1

Fixed

trixie

dovecot

Affected

Ubuntu

Unknown

bionic (esm-infra)

dovecot

Unknown

devel

dovecot

Unknown

focal (esm-infra)

dovecot

Unknown

jammy

dovecot

Unknown

noble

dovecot

Unknown

resolute

dovecot

Unknown

trusty (esm-infra-legacy)

dovecot

Unknown

xenial (esm-infra-legacy)

dovecot

Unknown

RHEL / CentOS

Affected

RHEL 8

dovecot.src

Affected

RHEL 9

dovecot.src

Affected

RHEL 10

dovecot.src

Affected

Alpine

Fixed

edge

dovecot: 2.4.5-r0

Fixed

v3.23

dovecot: 2.4.5-r0

Fixed

SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73208HIGH7.4
  • Dovecot logoDovecot
  • dovecot24-backend-sqlite
NoYesAug 28, 2026
CVE-2026-73209MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot24-fts-solr
NoYesAug 28, 2026
CVE-2026-52687MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot24-fts-flatcurve
NoYesAug 28, 2026
CVE-2026-42395MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot24
NoYesAug 28, 2026
CVE-2026-52681LOW3.1
  • Dovecot logoDovecot
  • dovecot24-fts-flatcurve
NoYesAug 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management