VYPR

managesieve

by Dovecot (software)

CVEs (3)

  • CVE-2026-33605HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance…

  • CVE-2026-27858HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install…

  • CVE-2026-40019MedAug 28, 2026
    risk 0.38cvss 5.9epss 0.00

    An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all…