Logo
vulnerabilityCVE-2026-27858
Name
CVE-2026-27858
Source
NVD ( link)Debian ( link)
Description
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dovecot
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
2.3.21.1
Exploitable
openwrt
master
2.3.21-r1
Exploitable
openwrt
openwrt-25.12
2.3.21-r1
Exploitable
yocto
kirkstone
2.3.14
Exploitable
yocto
master
2.4.4
Not Affected
yocto
scarthgap
2.3.21.1
Exploitable