
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73209 is a denial-of-service vulnerability in Open-Xchange's Dovecot IMAP server caused by uncontrolled recursion when processing crafted compressed data. An authenticated attacker can send specially crafted compressed data that exhausts the process stack, causing a crash and resulting in IMAP service disruption. Affected products include OX Dovecot Pro (versions 2.3.0–2.3.22.2, 3.0.0–3.0.7, and 3.1.0–3.1.6) and OX Dovecot CE (versions 2.3.0–2.4.5). The vulnerability was published on August 28, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-674 (Uncontrolled Recursion) and CWE-770 (Allocation of Resources Without Limits or Throttling), where the Dovecot IMAP process fails to properly bound recursive operations when decompressing attacker-supplied data. An authenticated attacker sends crafted compressed data over the network (low attack complexity, no user interaction required) that triggers unbounded recursion, ultimately exhausting the process stack and causing a crash. Exploitation requires valid credentials but no elevated privileges, limiting the attack surface to authenticated IMAP users. No publicly available proof-of-concept exploit code is known (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation terminates the affected Dovecot IMAP process, causing denial of service or degradation of IMAP functionality for all users of the affected server. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. In environments where Dovecot serves as the primary mail access layer, exploitation could disrupt email access for entire organizations until the service is restarted or the system is patched (GitHub Advisory).
There are no publicly available exploits or proof-of-concept code for this vulnerability, and no evidence of in-the-wild exploitation has been reported. The CVE status is listed as "Deferred" and NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.321%, reflecting a low near-term exploitation probability. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/var/log/mail.log or /var/log/dovecot.log) showing IMAP process termination; stack overflow or segmentation fault messages associated with the Dovecot IMAP process.dovecot or imap child process without a clear administrative cause; repeated process restarts in a short time window.Upgrade to a patched version of Dovecot: OX Dovecot Pro 2.3.22.2, 3.0.7, or 3.1.6; OX Dovecot CE 2.4.5 or later. As a workaround, restrict IMAP access to trusted and known users only to reduce the pool of potential authenticated attackers. Monitor for unexpected IMAP process crashes and implement service restart automation to minimize downtime if patching is delayed (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was disclosed by Open-Xchange (OX) and tracked across multiple Linux distribution security channels including SUSE, openSUSE, Red Hat, Debian, and Alpine Linux, all of which issued advisories or package updates. The oss-security mailing list and Full Disclosure list carried notifications shortly after the initial disclosure. Coverage has been routine and consistent with a medium-severity DoS finding, with no notable controversy or significant social media discussion observed.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
dovecot
devel
dovecot
focal (esm-infra)
dovecot
jammy
dovecot
noble
dovecot
resolute
dovecot
trusty (esm-infra-legacy)
dovecot
xenial (esm-infra-legacy)
dovecot
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."