Logo
vulnerabilityCVE-2026-40016
Name
CVE-2026-40016
Source
NVD ( link)Debian ( link)
Description
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dovecot
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.3.21.1
Exploitable
buildroot
master
2.3.21.1
Exploitable
openwrt
master
2.3.21-r1
Exploitable
openwrt
openwrt-25.12
2.3.21-r1
Exploitable
yocto
master
2.4.4
Not Affected
yocto
scarthgap
2.3.21.1
Exploitable