CVE-2026-40203: Open-Xchange GmbH Ox Dovecot CE
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.
Affected products
- Open-Xchange GmbH Ox Dovecot CE: from 2.3.0, before 2.4.5 (fixed in 2.4.5)
- Open-Xchange GmbH Ox Dovecot Pro: from 2.3.0, before 2.3.22.2 (fixed in 2.3.22.2); from 3.0.0, before 3.0.7 (fixed in 3.0.7); from 3.1.0, before 3.1.6 (fixed in 3.1.6)
Published 2026-08-28. Last modified 2026-09-03.