dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free
Published Aug 28, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.34%
Description
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.
Affected products
-
- Version 2.3.0StatusaffectedConstraints<2.4.5
- Version
-
- Version 2.3.0StatusaffectedConstraints<2.3.22.2
- Version 3.0.0StatusaffectedConstraints<3.0.7
- Version 3.1.0StatusaffectedConstraints<3.1.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Open-Xchange GmbH | OX Dovecot CE | unaffected |
| ||||||||||||
| Open-Xchange GmbH | OX Dovecot Pro | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 10
dovecot
Affected
Red Hat Enterprise Linux 6
dovecot
Out of support scope
Red Hat Enterprise Linux 7
dovecot
Affected
Red Hat Enterprise Linux 8
dovecot
Affected
Red Hat Enterprise Linux 9
dovecot
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dovecot | Affected | n/a |
| Red Hat Enterprise Linux 6 | dovecot | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | dovecot | Affected | n/a |
| Red Hat Enterprise Linux 8 | dovecot | Affected | n/a |
| Red Hat Enterprise Linux 9 | dovecot | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw requires an attacker to authenticate with valid credentials before it can be exploited, and exploitation additionally depends on the Sieve `editheader` extension being enabled, which is not Dovecot's default configuration. Because the CVSS attack vector requires low-privileged authentication (PR:L) rather than unauthenticated remote access, and the confirmed impact is primarily memory corruption leading to a crash of the mail delivery process, this issue is rated Important rather than Critical. Disabling the Sieve `editheader` extension fully mitigates the vulnerability without requiring a package update.
Red Hat mitigation
To mitigate this vulnerability, disable the Sieve `editheader` extension in the Dovecot configuration. After modifying the configuration, the Dovecot service must be restarted for the changes to take effect. Disabling this extension will remove its associated functionality.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.34% (0.00345) | 25.70th | v5 (v2026.06.15) |
| Aug 29, 2026 | 0.29% (0.00288) | 20.89th | v5 (v2026.06.15) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-42007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2525583 Issue Tracking
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0003.json vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42007
- https://www.cve.org/CVERecord?id=CVE-2026-42007
Change history (0)
No recorded changes yet.