CVE-2026-52687
Last modified
CVE-2026-52687 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | >= 2.3.11, < 2.3.22.2; >= 3.0.0, < 3.0.7; >= 3.1.0, < 3.1.6 |
| Open-Xchange GmbH | OX Dovecot CE | >= 2.3.11, < 2.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-52687?
How severe is CVE-2026-52687?
How do I fix CVE-2026-52687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52673SQL Injection vulnerability in Cboard v.0.4.2 and before all…6.5
- CVE-2026-5268An authentication bypass vulnerability exists in the default…9.1
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52681Sieve CPU resource usage is tracked in the compiled script, …3.1
- CVE-2026-52684If the auth responds very slowly and the records expire in b…3.7
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wild…7.5
- CVE-2026-5269In Ciena's Navigator Network Control Suite (NCS) and Manage …9.8
- CVE-2026-52690Spoofing replies to Recursor might mark an IP of an authorit…5.9
- CVE-2026-52691** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of S…8.8
- CVE-2026-52692Unauthenticated Sensitive Data Exposure in Affiliates Manage…7.5
- CVE-2026-52693Unauthenticated SQL Injection in eCommerce Product Catalog <…9.3
Are you affected by CVE-2026-52687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
