CVE-2026-40203: Open-Xchange GmbH Ox Dovecot CE

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

Affected products

  • Open-Xchange GmbH Ox Dovecot CE: from 2.3.0, before 2.4.5 (fixed in 2.4.5)
  • Open-Xchange GmbH Ox Dovecot Pro: from 2.3.0, before 2.3.22.2 (fixed in 2.3.22.2); from 3.0.0, before 3.0.7 (fixed in 3.0.7); from 3.1.0, before 3.1.6 (fixed in 3.1.6)

Published 2026-08-28. Last modified 2026-09-03.