Impact
A host that is listed as a trusted proxy can send forwarding information that contains a NUL byte. When the login process receives this data, it crashes and terminates the login attempt. The crash can lead to a degradation of login functionality or a complete denial of service for users trying to log in. The weakness is a classic resource exhaustion failure (CWE-400).
Affected Systems
The vulnerability affects Open‑Xchange GmbH OX Dovecot CE and OX Dovecot Pro deployments. Any installation that has not configured trusted proxy networks is not impacted. Systems that use the default trusted proxy configuration or have added external hosts to that list are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. No public exploits are known, and the EPSS score of < 1% suggests a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a host that is authorized as a trusted proxy; an attacker would need to control or compromise such a host or exploit a misconfiguration that allows untrusted hosts to appear as trusted proxies.
OpenCVE Enrichment