{"cves":[{"id":"CVE-2026-42392","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:29:15.726898+00:00","description":"\nAn attacker that has valid credentials can send an invalid IMAP URLFETCH\ncommand, which causes uninitialized memory to be included in the error\nresponse returned to the client. Process memory contents can be disclosed\nto the client, which may include sensitive data. Disable the IMAP URLAUTH\nfunctionality. Update to non-vulnerable version. No publicly available\nexploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42392"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/209a52b4d2ddb57eb1a02dcf216cb43414632582"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42391","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:48.851127+00:00","description":"\nAn unauthenticated attacker can send an IMAP ID command with a very large\nnumber of parameters before logging in, which causes memory and CPU usage\nto grow disproportionately. The login process can be terminated by the\nout-of-memory handling, which also terminates all other connections handled\nby the same process. This can cause degradation or denial of service for\nIMAP logins. Limit the number of connections handled by a single imap-login\nprocess. This has a performance impact though. Update to non-vulnerable\nversion. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42391"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/dbeb18dfc317be3c9839702c35c3fb77b7af90ff"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42008","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:48.851127+00:00","description":"\nForwarding information received from a host listed as a trusted proxy is\nnot kept separate from Dovecot's own authentication fields, so a value sent\nby that host can be injected as an internal authentication field. Any host\npermitted to act as a trusted proxy can authenticate as any user without\nknowing that user's password. This affects deployments whose password\ndatabase honours a field that permits authentication without a password.\nDeployments that do not configure trusted proxies are not affected.\nRestrict the list of trusted proxy networks to hosts that are fully under\nyour control. Update to non-vulnerable version. No publicly available\nexploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42008"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/ae95db16edbc9c671ca75ec43f9ef854415b3778","upstream: http://github.com/dovecot/core/commit/ca55238f3716da3f1df945616c12690e1919c10a"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42007","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:48.851127+00:00","description":"\nAn attacker that has valid credentials can use a Sieve script with the\neditheader extension to trigger a use-after-free in the mail editing code,\nand to write memory contents beyond the intended buffer into the delivered\nmail. This causes memory leak and opportunity to do memory corruption\nduring mail delivery, which can crash the delivery process and may allow\nexecution of arbitrary code in the context of that process. Disable the\nSieve editheader extension. Update to non-vulnerable version. No publicly\navailable exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42007"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/pigeonhole/commit/444972cfac3246b25c133c8868cfc013902cd1f3","upstream: http://github.com/dovecot/pigeonhole/commit/b49656de9a7b766b7fa2736ad8dbcf05057b3732"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40205","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that holds an OAuth2 token granting only part of the required\nscopes can authenticate, because when more than one scope is required in\nthe configuration, the remote token validation paths accept a token that\ncarries only one of them, while the local token validation path correctly\nrequires all of them. The configured authorization policy is not enforced,\nso a token that was granted only part of the required permissions is\naccepted where it should have been rejected. Use local token validation\nwhere tokens can be validated locally. Update to non-vulnerable version. No\npublicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40205"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/6bce5fdab7c1d6da569db6d5c9f48e37573fbdd8","upstream: http://github.com/dovecot/core/commit/de6f2c4e2393f856601074ec152dfa6c141042c4","upstream: http://github.com/dovecot/core/commit/d9aa14dcb24b5d35f1799d6da9c2ff286cca65b6","upstream: http://github.com/dovecot/core/commit/e953375267123848ff3969048c6cfc056f104860"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40204","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nNone None None No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40204"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/8d25b6d54c84d46f919ffde03a16afb72679bb9f","upstream: http://github.com/dovecot/core/commit/72d21003ae49ab7ed2f28438ec73303c0e95cea3","upstream: http://github.com/dovecot/pigeonhole/commit/4010e318939b557b0cdf7da3ae0f320d408aea65","upstream: http://github.com/dovecot/pigeonhole/commit/eec184745fabe1b2da0d5cc343f2a46710b70fc7"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40203","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:29:15.726898+00:00","description":"\nWhen IMAP compression is enabled, the same compression state is reused\nacross responses in a session, so response sizes depend on both\nattacker-supplied mail and other mail in the same mailbox. An attacker that\ncan send mail to a user and can also observe the sizes of that user's IMAP\ntraffic can confirm whether the body of a small message matches a guessed\ntext. Recovery of arbitrary unknown content was not demonstrated, but the\nattack can disclose whether a secret-like message body matches a candidate.\nDisable IMAP compression. Update to non-vulnerable version. No publicly\navailable exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40203"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/d46c651e4c6ca25d0e3c88761d0d5389beb7b075","upstream: http://github.com/dovecot/core/commit/c5fd46b0f64faada9a7424c291ab78cf99fe6090","upstream: http://github.com/dovecot/core/commit/370f4d49f1a3c62a7b7831ed9218bbb9755740ed","upstream: http://github.com/dovecot/core/commit/9725242241ba26bf509083528de9f4d8d869e65e","upstream: http://github.com/dovecot/core/commit/38350a7c284b8de7e02ca60e173abdb76848a216"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40019","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn unauthenticated attacker can send a truncated quoted argument to the\nManageSieve login process, which makes it spin in an infinite loop\nconsuming CPU. This can cause degradation or denial of service for Sieve\nscript management, and repeated connections can consume all available CPU\non the server. Monitor system for abnormal CPU usage and kill the offending\nprocess. Restrict network access to the ManageSieve service to trusted\nclients. Update to non-vulnerable version. No publicly available exploits\nare known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40019"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/pigeonhole/commit/61227ea6dca1ecd67fe4528f7fd0a3866876db07","upstream: http://github.com/dovecot/pigeonhole/commit/e5fe27a5785115b226391765a571c04ff01867ad","upstream: http://github.com/dovecot/pigeonhole/commit/e490109d0e28e5c4f0ffcdb7dc54463d53256d3c","upstream: http://github.com/dovecot/pigeonhole/commit/d04648f46e5e6b85883fc4c4cd66e4ac0f43257d","upstream: http://github.com/dovecot/pigeonhole/commit/afeed2afc787bba0f700b1de7f6889758ac30989"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40018","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:29:15.726898+00:00","description":"\nNone None None No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40018"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/769ad693450742ece44733e64a64122ab2843462","upstream: http://github.com/dovecot/core/commit/37da0240a316bd409d21b303f0a7e8627afd0789","upstream: http://github.com/dovecot/core/commit/3f9a9f117220b92edb4df0e9ef020092cdf29132","upstream: http://github.com/dovecot/core/commit/5bdfbe29cc07885ee931d9ed222ede7caf7324cb","upstream: http://github.com/dovecot/core/commit/f6bff126e890499214567cf8de2bf0eef3b0b7dd","upstream: http://github.com/dovecot/core/commit/77bc7af4cf6e788484423916ebf83b85338f621e","upstream: http://github.com/dovecot/core/commit/19572f9b36f3b612af105b0eef0f8a0cca398a53"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40017","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:29:15.726898+00:00","description":"\nAn attacker that can send mail to a user can craft a message header whose\nvalues are chosen to collide in an internal hash table, which makes the\nIMAP THREAD command consume CPU disproportionate to the size of the\nmessage. This is a separate issue from CVE-2026-40014 and is not addressed\nby that fix. Whenever a mail client issues a THREAD command on the affected\nmailbox, this can cause degradation or denial of service for IMAP. Monitor\nsystem for abnormal CPU usage, kill the offending process and remove the\noffending message from the affected mailbox. Update to non-vulnerable\nversion. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40017"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/a308c4bb8d7a3ba0a2c6a7bcd1456d6730261f60","upstream: http://github.com/dovecot/core/commit/7de0c5f0f5f386cbc11bfb30f422e575d80ed150","upstream: http://github.com/dovecot/core/commit/356468362b39241a5f35f9947fd2679cd09b1b22","upstream: http://github.com/dovecot/core/commit/ad4f4f95202d4030f1b10ba2bbc0d21bf97bfa79","upstream: http://github.com/dovecot/core/commit/9896a67986a405c33c2a7fcda030d451df689503","upstream: http://github.com/dovecot/core/commit/9c50e0f64f35485f27208732cc8c694add5fc133","upstream: http://github.com/dovecot/core/commit/d34ac20f89bef60f91cd898e431018ee57061125","upstream: http://github.com/dovecot/core/commit/0ad27eb7e68e9999f7979d38b5d2d87c18bc9219","upstream: http://github.com/dovecot/core/commit/ac5ee9f37a6afadf23722a7ed55932a6afcf6ffe","upstream: http://github.com/dovecot/core/commit/6de4987bd0d4841708d142d1b8e6ca966959e923","upstream: http://github.com/dovecot/core/commit/618744e18bd4fb2942070b3a2cd2db819b12506f","upstream: http://github.com/dovecot/core/commit/e9fb943f886635409d21f936f97b35df2f61f373"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40015","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:48.851127+00:00","description":"\nAn attacker that has valid credentials can open many connections to the\nimap-hibernate service and send invalid commands, which can intermittently\ncause an out-of-bounds read and crash the process. The crash interrupts\nhibernated IMAP sessions handled by the affected process, which can cause\ndegradation of service for IMAP. Disable IMAP hibernation. Update to\nnon-vulnerable version. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40015"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/a880d0bc5600d338cc6fb21e30a16a7257687b64","upstream: http://github.com/dovecot/core/commit/e767537bfa1bc71b69312691152c3d6bc92f8a50"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40014","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that can send mail to a user can craft a message header that\nmakes the IMAP THREAD command consume CPU disproportionate to the size of\nthe message. When a mail client issues a THREAD command on the affected\nmailbox, this can cause degradation or denial of service for IMAP. Monitor\nsystem for abnormal CPU usage, kill the offending process and remove the\noffending message from the affected mailbox. Update to non-vulnerable\nversion. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40014"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/fe6b8a4c5305b106ae68a197ee301d8fe3f38672","upstream: http://github.com/dovecot/core/commit/2818f84d9e4f93d9997f9cc7b1cc55a7cacb85a0"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40013","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that has valid credentials can submit a Sieve script containing\nan extreme numeric literal, which causes an out-of-bounds write when the\nManageSieve service compiles the script. This causes memory corruption and\nan observed crash of the ManageSieve process, resulting in denial of\nservice for script management. This might be able to be used for remote\ncode execution. Disable the ManageSieve service if users do not need remote\nSieve script management. Update to non-vulnerable version. No publicly\navailable exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40013"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/pigeonhole/commit/3f0af33abcc9911b586be9b5adc0afb3e9f18d25"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33607","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that has valid credentials can use IMAP LIST command to consume\nCPU. This can cause degradation or denial of service for IMAP. Monitor\nsystem for abnormal CPU usage and kill the offending process and lock\naccount. Alternatively install fixed version. No publicly available\nexploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33607"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/19f6818fc2f2e05ccbb4eedbfb13234cc220a956","upstream: http://github.com/dovecot/core/commit/1b0a76c5d0729c66666ed91a00e378129851634a","upstream: http://github.com/dovecot/core/commit/e487bab78ac4b8c38621f29e56ffb5ac2e739658","upstream: http://github.com/dovecot/core/commit/8a4879fc5d8adf29b741a3b72cba54b9325816e7","upstream: http://github.com/dovecot/core/commit/eee6c367021f7524f55cc0a4cc344dd95f784767","upstream: http://github.com/dovecot/core/commit/0e1836a2ec6724fe2f745c629113b71975fd8673"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33606","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:29:15.726898+00:00","description":"\nMail content stored by a user can be crafted so that it is interpreted as\ndsync protocol commands when an administrator later runs dsync with the\nstream protocol, for example during a migration. Injected commands can\nmodify mailbox state on the destination during migration or replication,\nincluding internal mailbox attributes that a user should not be able to set\ndirectly. It can also cause dsync errors. Avoid running dsync with the\nstream protocol on mailboxes with untrusted content. Update to\nnon-vulnerable version. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33606"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/116bab8d7e4acedae628cc88772049bc08a36047","upstream: http://github.com/dovecot/core/commit/3f73c11d0ebcfebbda0225699f30513efd8c77f4"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33605","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn unauthenticated attacker can crash the ManageSieve login process by\nsending a small malformed command before authenticating. If running in\nhigh-security mode (default for community releases), only the attacker's\nown connection is terminated. If running in high-performance mode (default\nfor Pro releases), all connections handled by the same managesieve-login\nprocess are terminated. Repeating the attack can cause denial of service\nfor Sieve script management. Restrict network access to the ManageSieve\nservice to trusted clients. Update to non-vulnerable version. No publicly\navailable exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33605"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/pigeonhole/commit/4ef39dbda7ed2c4f48e8aa91420075132ea723cf","upstream: http://github.com/dovecot/pigeonhole/commit/19dc05d272c7d30cd80828f304dd9e9e7516063c"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33604","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that can get Dovecot to relay a message, for example through\nSieve redirect or submission relay, can use a crafted line ending in the\nmessage body to bypass the outbound protection that prevents message\ncontent from being interpreted as SMTP commands. A downstream mail server\nthat hasn't yet fixed the SMTP smuggling vulnerability can be tricked into\ntreating part of the message body as new SMTP commands, allowing injection\nof spoofed email. This is the same vulnerability class as CVE-2023-51764\nand CVE-2023-51766. Where you control the receiving mail servers, ensure\nthey reject bare carriage returns in message data. Update to non-vulnerable\nversion. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33604"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/8e254544cd8314092b4e3b2e7654df34b73e721b","upstream: http://github.com/dovecot/core/commit/b5921303c9ba9ae51b68a3a9f0ef2be1fdb35cc0","upstream: http://github.com/dovecot/core/commit/0e9af24dc0d191be3c8ba7747a00a54337c6fd9a","upstream: http://github.com/dovecot/core/commit/5d8bea193dec2d2a065868f383738ba6625f839e"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33263","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:48.851127+00:00","description":"\nWhen mail_max_userip_connections is set (default 10) and reached,\nsubmission-login can crash with epoll() panic caused by file descriptor\nhandling issues. If running in high-security mode (default for community\nreleases), only the new submission connection gets terminated. If running\nin high-performance mode (default for Pro releases), all connections\nhandled by the submission-login process will be terminated. The crashes can\ncause failure for user to send a message, or it can cause duplicate\nmessages to be sent. If TLS is not used (in the backend server processing\nthe submission), duplicate deliveries cannot happen, because the crash can\nonly happen at AUTH stage. Limit the number of connections handled by\nsingle submission-login process. This has a performance impact though.\nUpdate to non-vulnerable version. No publicly available exploits are known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33263"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/9cbe5c9a5e0526b799c98e0e299821a3390599d3","upstream: http://github.com/dovecot/core/commit/a2b74bac07c8a231b859203fe2e624f3f0806e65","upstream: http://github.com/dovecot/core/commit/2a1ae65f59bd462b18d815e1fb5971bb4be86d52","upstream: http://github.com/dovecot/core/commit/cae8cf70d24939f515e2a039acb0b8e2fea5ccb2","upstream: http://github.com/dovecot/core/commit/432177f997e74843ba8b3c271d28697675b34a0f"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-27852","published":"2026-08-28T00:00:00","updated_at":"2026-09-10T17:28:58.058904+00:00","description":"\nAn attacker that can send mail to a user can craft a message whose headers\ncontain a very large number of email addresses or MIME parameters, which\ncauses excessive memory usage when the message is later parsed. The message\nis still delivered, but reading it over IMAP can exhaust the memory limit\nof the process and terminate it, causing denial of service for the affected\nuser. Update to non-vulnerable version. No publicly available exploits are\nknown.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27852"],"bugs":[""],"patches":{"dovecot":["upstream: http://github.com/dovecot/core/commit/a67a9464acad60a337a31ac6fb3f36df95f002eb","upstream: http://github.com/dovecot/core/commit/2837d1e1fe5af07d09c10f6c09fb7fcca85a89c8","upstream: http://github.com/dovecot/core/commit/be07a3c783fd9359ddd5b183becb0da17f3d743c","upstream: http://github.com/dovecot/core/commit/e4b8d305ce0dd48843e69b8b3b235f275e89c93f","upstream: http://github.com/dovecot/core/commit/33461dedda0f09793b2b7c8a7990935fa322a897","upstream: http://github.com/dovecot/core/commit/17e5f5d27b3b35fd9195da77feb555fbbdc08263","upstream: http://github.com/dovecot/core/commit/0a7a98851b0f49759780156e2bfd0e4ec19752fc","upstream: http://github.com/dovecot/core/commit/94454090c12b6a4081fb75559e24ab024a66cf27","upstream: http://github.com/dovecot/core/commit/fc7a4eef0f7166acb4aafe995930ddc0da9f7cf6","upstream: http://github.com/dovecot/core/commit/c5282786988d6be67d74067908f27e5480938a00","upstream: http://github.com/dovecot/core/commit/a973e668bcdbfba8c0ceb1ed74b091b82cab501a","upstream: http://github.com/dovecot/core/commit/a1baaddc23493a9061fe5430085b36ce8543bae6","upstream: http://github.com/dovecot/core/commit/69868fbdb06aa08ee74b1031d5cb461a73394006"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-81934","published":"2026-08-27T20:18:00","updated_at":"2026-09-16T16:34:18.485740+00:00","description":"\nRedis contains a use-after-free vulnerability in the\n'tlsProcessPendingData()' function, which handles the TLS pending-data list\nif Redis is configured with TLS support. A remote, unauthenticated attacker\nmay be able to execute arbitrary commands with the privileges of the Redis\nserver.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-81934","https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 (8.8.2)","https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834","https://github.com/v12-security/pocs/tree/main/redis/server_ssl","https://raw.githubusercontent.com/redis/redis/8.10/00-RELEASENOTES","https://raw.githubusercontent.com/redis/redis/8.2/00-RELEASENOTES","https://raw.githubusercontent.com/redis/redis/8.4/00-RELEASENOTES","https://raw.githubusercontent.com/redis/redis/8.6/00-RELEASENOTES","https://raw.githubusercontent.com/redis/redis/8.8/00-RELEASENOTES"],"bugs":[""],"patches":{"redis":[]},"tags":{},"packages":[{"name":"redis","source":"https://ubuntu.com/security/cve?package=redis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redis","debian":"https://tracker.debian.org/pkg/redis","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":2500,"limit":20,"total_results":79316}