GHSA-xr7v-hj32-mr4rHighCVSS 7.5

Attacker can send a specifically crafted message before authentication that causes managesieve to...

Published
March 27, 2026
Last Modified
June 30, 2026

🔗 CVE IDs covered (1)

📋 Description

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

🔗 References (20)