Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
Any version
affected
Any version
affected
Any version
affected
Description
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Problem types
Uncontrolled Resource Consumption
Product status
Any version
Any version
Any version
References
documentation.open-xchange.com/...26/oxdc-adv-2026-0001.json