CVE-2026-33605: Open-Xchange GmbH Ox Dovecot CE

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

Affected products

  • Open-Xchange GmbH Ox Dovecot CE: from 2.3.0, before 2.4.5 (fixed in 2.4.5)
  • Open-Xchange GmbH Ox Dovecot Pro: from 2.3.0, before 2.3.22.2 (fixed in 2.3.22.2); from 3.0.0, before 3.0.7 (fixed in 3.0.7); from 3.1.0, before 3.1.6 (fixed in 3.1.6)

Published 2026-08-28. Last modified 2026-09-03.