VDB
CVE-2026-42007
CVE-2026-42007
PUBLISHED
CVSS 9.1 CRITICAL
Reported by OX · Published August 28, 2026
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | 2.3.0, 3.0.0, 3.1.0 |
| Open-Xchange GmbH | OX Dovecot CE | 2.3.0 |
| alpine | dovecot | 0, 0, 0 |
| Open-Xchange GmbH | OX Dovecot Pro | 2.3.0, 3.0.0, 3.1.0 |
| Open-Xchange GmbH | OX Dovecot CE | 2.3.0 |
Timeline
- Aug 28, 2026 CVE Published
- Aug 29, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 29, 2026 EPSS Score
- Oct 1, 2026 EPSS Score