CVE-2026-27857: High severity Dovecot dovecot vulnerability
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27857?
The severity of CVE-2026-27857 is rated high, with a score of 7.5.
How do I fix CVE-2026-27857?
To fix CVE-2026-27857, it is recommended to update to the latest version of Open-Xchange Dovecot or apply the relevant security patches.
What kind of attack is associated with CVE-2026-27857?
CVE-2026-27857 is associated with a denial-of-service attack due to excessive memory usage from crafted NOOP commands.
What are the potential impacts of CVE-2026-27857?
The potential impacts of CVE-2026-27857 include increased memory usage leading to client disconnections and possible service disruptions.
Is CVE-2026-27857 exploitable remotely?
Yes, CVE-2026-27857 is exploitable remotely as it allows attackers to connect and send specifically crafted commands.