Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-27 09:16
Updated : 2026-03-30 13:26
NVD link : CVE-2026-27858
Mitre link : CVE-2026-27858
CVE.ORG link : CVE-2026-27858
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
