[Git][security-tracker-team/security-tracker][master] Add second half of dovecot issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 21:28:53 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c127ee5c by Salvatore Bonaccorso at 2026-08-28T22:27:29+02:00
Add second half of dovecot issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -156,9 +156,11 @@ CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard libr
 CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
 	TODO: check
 CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73209-imap-login-crash-self-recursion-on-zero-output-decompress-chunks
 CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73208-auth-db-oauth2-aud-claim-used-as-fallback-for-missing-scope-claim
 CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
@@ -184,9 +186,11 @@ CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r
 CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
 	TODO: check
 CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52687-imap-compress-zstd-can-cause-excessive-memory-usage
 CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
 CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of  ...)
 	TODO: check
 CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -194,34 +198,46 @@ CVE-2026-4378 (Improper neutralization of input during web page generation ('cro
 CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42395-single-nul-byte-xclient-forward-payload-crashes
 CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully  ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42393-doveadm-password-or-api-key-length-can-still-be-leaked-with-timing-comparisons
 CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
 CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
 CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy  ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
 CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce
 CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
 	NOT-FOR-US: Synology
 CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40205-oauth2-passdb-scope-enforcement-bypass-via-or-semantics-in-remote-validation-path
 CVE-2026-40204 (None None None No publicly available exploits are known.)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
 CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
 CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40019-v2-4-3-regression-managesieve-login-pre-auth-infinite-loop
 CVE-2026-40018 (None None None No publicly available exploits are known.)
 	- dovecot <unfixed>
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40018-mysql-multi-byte-escaping-wrong
 CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40017-imap-thread-o-m3-cpu-dos-via-crc32-hash-collision-in-strmap-mail-index-strmap-c-hash2-c
 CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
-	TODO: check
+	- dovecot <unfixed>
+	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
 CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
 	- dovecot <unfixed>
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c127ee5cebfa38d4d5d4aafb5fd645c1b2a4bff1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c127ee5cebfa38d4d5d4aafb5fd645c1b2a4bff1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/85efaa27/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list