Description
A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A host that is listed as a trusted proxy can send forwarding information that contains a NUL byte. When the login process receives this data, it crashes and terminates the login attempt. The crash can lead to a degradation of login functionality or a complete denial of service for users trying to log in. The weakness is a classic resource exhaustion failure (CWE-400).

Affected Systems

The vulnerability affects Open‑Xchange GmbH OX Dovecot CE and OX Dovecot Pro deployments. Any installation that has not configured trusted proxy networks is not impacted. Systems that use the default trusted proxy configuration or have added external hosts to that list are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity. No public exploits are known, and the EPSS score of < 1% suggests a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a host that is authorized as a trusted proxy; an attacker would need to control or compromise such a host or exploit a misconfiguration that allows untrusted hosts to appear as trusted proxies.

Generated by OpenCVE AI on September 1, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a non‑vulnerable release of OX Dovecot
  • Restrict the list of trusted proxy networks to hosts that are fully under your control
  • Remove or disable trusted proxy configuration if it is not required for your deployment

Generated by OpenCVE AI on September 1, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Null Byte Crash in Trusted Proxy Forwarding Causing Denial of Service in OX Dovecot dovecot: Dovecot: Denial of Service via NUL byte in forwarding information
Weaknesses CWE-170
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Null Byte Crash in Trusted Proxy Forwarding Causing Denial of Service in OX Dovecot

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Open-xchange Ox Dovecot Ce Ox Dovecot Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T15:53:43.599Z

Reserved: 2026-04-27T08:53:58.839Z

Link: CVE-2026-42395

cve-icon Vulnrichment

Updated: 2026-08-28T14:32:29.220Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:29.887

Modified: 2026-09-03T18:13:44.643

Link: CVE-2026-42395

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-28T10:12:29Z

Links: CVE-2026-42395 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:45:04Z

Weaknesses
  • CWE-170

    Improper Null Termination

  • CWE-400

    Uncontrolled Resource Consumption