CVE Tools

Ox Dovecot Pro

44 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ox Dovecot Pro, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

Ox Dovecot Pro CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ox Dovecot Pro CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-010
2026-020
2026-0311
2026-040
2026-055
2026-060
2026-070
2026-0824
2026-090

Severity

How the 44 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical12%
  • High1227%
  • Medium2557%
  • Low614%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ox Dovecot Pro.

  1. CVE-2026-73209An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradat...6.5
  2. CVE-2026-73208An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and c...7.4
  3. CVE-2026-52687An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The...6.5
  4. CVE-2026-52681Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are al...3.1
  5. CVE-2026-42395A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can ca...4.3
  6. CVE-2026-42393The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm serv...3.1
  7. CVE-2026-42392An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory conte...4.3
  8. CVE-2026-42391An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can...7.5
  9. CVE-2026-42008Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal auth...4.3
  10. CVE-2026-42007An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended bu...9.1
  11. CVE-2026-40205An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation pat...5.9
  12. CVE-2026-40204None None None No publicly available exploits are known.3.1
  13. CVE-2026-40203When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An ...3.7
  14. CVE-2026-40018None None None No publicly available exploits are known.7.4
  15. CVE-2026-40017An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store