[Git][security-tracker-team/security-tracker][master] Add first batch of new dovecot issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 21:04:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
db8c6350 by Salvatore Bonaccorso at 2026-08-28T22:03:50+02:00
Add first batch of new dovecot issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -216,15 +216,18 @@ CVE-2026-40203 (When IMAP compression is enabled, the same compression state is
 CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
 	TODO: check
 CVE-2026-40018 (None None None No publicly available exploits are known.)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40018-mysql-multi-byte-escaping-wrong
 CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
 	TODO: check
 CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
 	TODO: check
 CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c
 CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40013-pigeonhole-stack-buffer-underflow-in-pigeonhole-managesieve-checkscript-putscript
 CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows unauthenticated ...)
@@ -246,17 +249,23 @@ CVE-2026-37237 (vLLM up to and including 0.17.0 allows remote attackers to cause
 CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...)
 	TODO: check
 CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33607-dovecot-imap-list-match-sub-exponential-backtracking-%E2%80%94-cpu-denial-of-service
 CVE-2026-33606 (Mail content stored by a user can be crafted so that it is interpreted ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33606-dsync-mail-content-can-cause-dsync-protocol-injection
 CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
 CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33604-smtp-smuggling-via-missing-dot-stuffing-after-bare-carriage-return
 CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor
 CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-27852-dos-by-sending-mail-with-bad-header
 CVE-2026-19423 (The Ultimate Member  WordPress plugin before 2.13.0 does not validate  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db8c635026e84443b05ae96dba6986d2e0881054

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db8c635026e84443b05ae96dba6986d2e0881054
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/fb5cce8b/attachment.htm>


More information about the debian-security-tracker-commits mailing list