CVE-2026-52687: Medium severity Dovecot IMAP imap-login vulnerability

Published Aug 28, 2026
·
Updated

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.

Affected Software

1 affected component
Dovecot IMAP imap-login

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable IMAP compression to prevent attackers with valid credentials from selecting a compression algorithm that causes excessive memory use during decompression.

    IMAP server IMAP compression = disabled
  2. Compensating control

    Limit the number of connections handled by a single imap-login process (noting this has a performance impact) to reduce the impact of memory exhaustion.

Event History

Aug 28, 2026
CVE Published
via MITRE·10:12 AM
Data Sourced
via MITRE·10:12 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs valid IMAP credentials and network access to establish IMAP connections. No user interaction is required.

2

Are systems affected by default?

The issue requires IMAP compression to be enabled. Disabling IMAP compression prevents the described attack path.

3

What can be done if an update cannot be applied immediately?

Disable IMAP compression. Alternatively, limit the number of connections handled by each imap-login process, recognizing that this can reduce performance.

4

How does exploitation affect the service?

A small number of crafted compressed IMAP connections can exhaust the process memory limit, terminate that process, and drop all connections it handles. This can degrade or deny IMAP service.

5

Are public exploits available?

No publicly available exploits are known.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203