CVE-2026-40019
Last modified
CVE-2026-40019 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot CE | >= 2.4.3, < 2.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40019?
How severe is CVE-2026-40019?
How do I fix CVE-2026-40019?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40013An attacker that has valid credentials can submit a Sieve sc…4.3
- CVE-2026-40014An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40015An attacker that has valid credentials can open many connect…4.3
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-40017An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40018None None None No publicly available exploits are known.7.4
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
- CVE-2026-40021Apache Log4net's XmlLayout https://logging.apache.org/log4n…5.3
- CVE-2026-40022When authentication is enabled on the Apache Camel embedded …8.2
- CVE-2026-40023Apache Log4cxx's XMLLayout https://logging.apache.org/log4c…5.3
- CVE-2026-40024The Sleuth Kit through 4.14.0 contains a path traversal vuln…7.1
Are you affected by CVE-2026-40019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
