CVE-2026-27859Uncontrolled Resource Consumption in Dovecot

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 84.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMar 31

Description

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available exploits are known.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/dovecot< dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)
Debiandovecot/dovecot< 1:2.3.19.1+dfsg1-2.1+deb12u2+1
Ubuntudovecot/dovecot< 1:2.3.16+dfsg1-3ubuntu2.7+2

🔴Vulnerability Details

3
OSV
dovecot vulnerabilities2026-03-31
OSV
CVE-2026-27859: A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU2026-03-27
GHSA
GHSA-3rfp-26pp-jqjf: A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU2026-03-27

📋Vendor Advisories

3
Ubuntu
Dovecot vulnerabilities2026-03-31
Red Hat
dovecot: Dovecot: Denial of Service via excessive RFC 2231 MIME parameters2026-03-27
Debian
CVE-2026-27859: dovecot - A mail message containing excessive amount of RFC 2231 MIME parameters causes LM...2026

🕵️Threat Intelligence

11
Wiz
CVE-2026-27858 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-0394 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-27856 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-27855 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-59032 Impact, Exploitability, and Mitigation Steps | Wiz