CVE-2026-40017
Last modified
CVE-2026-40017 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | >= 2.3.0, < 2.3.22.2; >= 3.0.0, < 3.0.7; >= 3.1.0, < 3.1.6 |
| Open-Xchange GmbH | OX Dovecot CE | >= 2.3.0, < 2.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40017?
How severe is CVE-2026-40017?
How do I fix CVE-2026-40017?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40011An attacker sending a large number of crafted DNS queries mi…3.7
- CVE-2026-40012ECS zero scoped answers are stored in the packet cache while…5.3
- CVE-2026-40013An attacker that has valid credentials can submit a Sieve sc…4.3
- CVE-2026-40014An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40015An attacker that has valid credentials can open many connect…4.3
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-40018None None None No publicly available exploits are known.7.4
- CVE-2026-40019An unauthenticated attacker can send a truncated quoted argu…5.9
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
- CVE-2026-40021Apache Log4net's XmlLayout https://logging.apache.org/log4n…5.3
- CVE-2026-40022When authentication is enabled on the Apache Camel embedded …8.2
Are you affected by CVE-2026-40017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
