Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4556-1 | dovecot security update |
Debian DSA |
DSA-6197-1 | dovecot security update |
Ubuntu USN |
USN-8136-1 | Dovecot vulnerabilities |
Thu, 30 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dovecot
Dovecot dovecot Open-xchange dovecot |
|
| CPEs | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
|
| Vendors & Products |
Dovecot
Dovecot dovecot Open-xchange dovecot |
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Pro |
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Allocation Denial of Service via Crafted Managesieve Message | dovecot: denial of service via crafted message before authentication |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Allocation Denial of Service via Crafted Managesieve Message |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known. | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T12:37:09.762Z
Reserved: 2026-02-24T08:46:09.374Z
Link: CVE-2026-27858
Updated: 2026-03-27T12:37:04.235Z
Status : Analyzed
Published: 2026-03-27T09:16:20.073
Modified: 2026-04-30T17:40:17.243
Link: CVE-2026-27858
OpenCVE Enrichment
Updated: 2026-03-30T07:59:46Z
Debian DLA
Debian DSA
Ubuntu USN