https://seclists.org/oss-sec/2026/q3/604: Dovecot Security Advisory 3/2026
Published Aug 28, 2026
·Updated
Affected Software
5 affected components
Open-Xchange OX Dovecot Pro core>=2.3.0<2.3.22.2
Open-Xchange OX Dovecot Pro core>=3.0.0<3.0.7
Open-Xchange OX Dovecot Pro core>=3.1.0<3.1.6
Open-Xchange OX Dovecot CE core>=2.3.0<2.4.5
Open-Xchange OX Dovecot CE core>=2.4.3<2.4.5
Frequently Asked Questions
1
Is a default configuration affected?
Yes. The mail_max_userip_connections setting defaults to 10, and submission-login can crash when that limit is reached.
2
What access does an attacker need to trigger the issue?
The CVSS vector indicates network reachability and low privileges are required. No user interaction is required.
3
What is the practical impact of successful exploitation?
The reported outcome is a submission-login crash caused by a bad file descriptor error after the per-user-IP connection limit is reached. The CVSS assessment rates the impact as availability-only and low; confidentiality and integrity impacts are listed as none.