Description
When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.
Published: 2026-08-28
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch/Disable
AI Analysis

Impact

The vulnerability occurs when IMAP compression is enabled on Open‑Xchange Dovecot servers. The same compression state is reused across IMAP responses within a single session, causing response sizes to vary depending on both the attacker’s mail and other emails present in the target mailbox. An attacker who can inject mail into a victim’s inbox and can observe the size of the victim’s IMAP traffic can use these size variations to confirm whether the body of a small message matches a guessed string. While arbitrary content recovery was not demonstrated, the attack can effectively disclose whether a secret‑like message body matches a candidate. The weakness is an information‑exposure flaw (CWE‑200 and CWE‑205).

Affected Systems

The affected vendors are Open‑Xchange GmbH, specifically the OX Dovecot CE and OX Dovecot Pro products. The vulnerability applies to versions that have IMAP compression enabled, but the precise version range is not specified in the advisory. Users should verify that their Dovecot deployment is running the latest non‑vulnerable release when available.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity under the current assessment. No publicly available exploits exist, and the EPSS score is < 1%, indicating a very low likelihood of exploitation. It is listed as not in the CISA KEV catalog. The most probable attack path requires an attacker to send email to the victim and monitor the victim’s IMAP traffic, which may be achievable in shared or compromised environments. Given the low CVSS but possible covert nature of the disclosure, administrators should address the issue promptly.

Generated by OpenCVE AI on September 1, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable IMAP compression to prevent compression state reuse
  • Update to the latest non‑vulnerable Dovecot release
  • Verify that the server is correctly configured to reject or limit unsolicited mail from untrusted sources

Generated by OpenCVE AI on September 1, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title IMAP Compression Reuse Allows Recipient‑Dependent Information Disclosure dovecot: Dovecot: Information disclosure via IMAP compression side-channel
Weaknesses CWE-205
References
Metrics threat_severity

None

threat_severity

Low


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title IMAP Compression Reuse Allows Recipient‑Dependent Information Disclosure

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Open-xchange Ox Dovecot Ce Ox Dovecot Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T14:57:07.686Z

Reserved: 2026-04-10T07:11:39.060Z

Link: CVE-2026-40203

cve-icon Vulnrichment

Updated: 2026-08-28T14:57:03.836Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:28.897

Modified: 2026-09-03T18:13:44.643

Link: CVE-2026-40203

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-28T10:12:22Z

Links: CVE-2026-40203 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-205

    Observable Behavioral Discrepancy