← Terug naar overzicht

CVE-2026-42007 affects Dovecot mail server, where an authenticated attacker can exploit the Sieve script editheader extension to trigger a use-after-free vulnerability in the mail editing code. The flaw allows writing memory contents beyond intended buffer boundaries into delivered mail, resulting in memory leaks and potential memory corruption during mail delivery. This can crash the delivery process and may allow execution of arbitrary code within the context of that process. The vulnerability requires valid credentials to exploit, limiting the attack surface somewhat. Mitigations include disabling the Sieve editheader extension or updating to a non-vulnerable version of Dovecot. No publicly available exploits are currently known. The advisory is published by Open-Xchange, the maintainer of Dovecot.

Affected products

  • Dovecot

Related CVE's

  • CVE-2026-42007

Categories

  • Email & Messaging