An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated IMAP ID Command Causes DoS via Excessive Parameters dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Important


Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated IMAP ID Command Causes DoS via Excessive Parameters

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T15:54:09.305Z

Reserved: 2026-04-27T08:53:58.839Z

Link: CVE-2026-42391

cve-icon Vulnrichment

Updated: 2026-08-28T14:42:09.265Z

cve-icon NVD

Status : Received

Published: 2026-08-28T12:16:29.503

Modified: 2026-08-28T20:17:30.280

Link: CVE-2026-42391

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-28T10:12:27Z

Links: CVE-2026-42391 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:17:34Z

Weaknesses