Sploitus

CVE-2026-42006

No indexed exploits for CVE-2026-42006 yet

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

Dovecot
< 2.4.4
Open-xchange Dovecot
< 3.1.5
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.6% (48th percentile)
Weakness
CWE-770, CWE-400
NVD status
Modified
Published
2026-05-12
CVE-2026-42006 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-42006 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-42006 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.