[Git][security-tracker-team/security-tracker][master] Add second half of dovecot issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 21:28:53 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c127ee5c by Salvatore Bonaccorso at 2026-08-28T22:27:29+02:00
Add second half of dovecot issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -156,9 +156,11 @@ CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard libr
CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
TODO: check
CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73209-imap-login-crash-self-recursion-on-zero-output-decompress-chunks
CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73208-auth-db-oauth2-aud-claim-used-as-fallback-for-missing-scope-claim
CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
NOT-FOR-US: WordPress plugin
CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
@@ -184,9 +186,11 @@ CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r
CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
TODO: check
CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52687-imap-compress-zstd-can-cause-excessive-memory-usage
CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of ...)
TODO: check
CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -194,34 +198,46 @@ CVE-2026-4378 (Improper neutralization of input during web page generation ('cro
CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42395-single-nul-byte-xclient-forward-payload-crashes
CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42393-doveadm-password-or-api-key-length-can-still-be-leaked-with-timing-comparisons
CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce
CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
NOT-FOR-US: Synology
CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40205-oauth2-passdb-scope-enforcement-bypass-via-or-semantics-in-remote-validation-path
CVE-2026-40204 (None None None No publicly available exploits are known.)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40019-v2-4-3-regression-managesieve-login-pre-auth-infinite-loop
CVE-2026-40018 (None None None No publicly available exploits are known.)
- dovecot <unfixed>
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40018-mysql-multi-byte-escaping-wrong
CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40017-imap-thread-o-m3-cpu-dos-via-crc32-hash-collision-in-strmap-mail-index-strmap-c-hash2-c
CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
- TODO: check
+ - dovecot <unfixed>
+ NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
- dovecot <unfixed>
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c127ee5cebfa38d4d5d4aafb5fd645c1b2a4bff1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c127ee5cebfa38d4d5d4aafb5fd645c1b2a4bff1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/85efaa27/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list