Issued at: 2026-10-10
Updated at: 2026-10-10
Advisory content derived from Red Hat RHSA-2026:79371, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: dovecot security update
Description
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.
Security Fix(es):
* dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters (CVE-2026-42391)
* dovecot: Dovecot: Authentication bypass via incorrect OAuth2 token validation (CVE-2026-73208)
* dovecot: Dovecot: Denial of service via crafted email headers (CVE-2026-27852)
* dovecot: Dovecot: Denial of Service via truncated quoted argument in ManageSieve (CVE-2026-40019)
* dovecot: Dovecot: Denial of Service and potential message duplication via connection limit exhaustion (CVE-2026-33263)
* dovecot: Dovecot: Denial of Service in ManageSieve login process (CVE-2026-33605)
* dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free (CVE-2026-42007)
* dovecot: Dovecot: MySQL multi-byte escaping wrong (CVE-2026-40018)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.