CVE-2026-42391: High severity Dovecot IMAP login (imap-login) vulnerability

Published Aug 28, 2026
·
Updated

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.

Affected Software

1 affected component
Dovecot IMAP login (imap-login)

Event History

Aug 28, 2026
CVE Published
via MITRE·10:12 AM
Data Sourced
via MITRE·10:12 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated network client that can reach the Dovecot IMAP login service can send the malicious IMAP ID command before logging in. No user interaction or valid credentials are required.

2

What is the operational impact of a successful attack?

The attack can drive disproportionate memory and CPU consumption in an imap-login process. If out-of-memory handling terminates that process, all other connections handled by the same process are also terminated, degrading or denying IMAP login service.

3

What can be done if an update cannot be applied immediately?

Limit the number of connections handled by each imap-login process to reduce the number of clients affected when a process is terminated. This mitigation has a performance impact.

4

Are public exploits available?

No publicly available exploits are known.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203