Back

CRITICAL

dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free

Published Aug 28, 2026

Description

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

Affected products

Remediation

Red Hat statement

This flaw requires an attacker to authenticate with valid credentials before it can be exploited, and exploitation additionally depends on the Sieve `editheader` extension being enabled, which is not Dovecot's default configuration. Because the CVSS attack vector requires low-privileged authentication (PR:L) rather than unauthenticated remote access, and the confirmed impact is primarily memory corruption leading to a crash of the mail delivery process, this issue is rated Important rather than Critical. Disabling the Sieve `editheader` extension fully mitigates the vulnerability without requiring a package update.

Red Hat mitigation

To mitigate this vulnerability, disable the Sieve `editheader` extension in the Dovecot configuration. After modifying the configuration, the Dovecot service must be restarted for the changes to take effect. Disabling this extension will remove its associated functionality.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OX
Published Aug 28, 2026
Updated Aug 28, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Deferred
Modified Sep 3, 2026
Red Hat
Severity Important
Public date Aug 28, 2026