CVE-2026-33606
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
- EPSS probability
- 0.20%
- CWE
- CWE-93
- Published
- 2026-08-28
- Last modified
- 2026-08-28
Affected products
- Open-Xchange GmbH OX Dovecot Pro
- Open-Xchange GmbH OX Dovecot Pro
- Open-Xchange GmbH OX Dovecot Pro
- Open-Xchange GmbH OX Dovecot CE
Weakness type
Related vulnerabilities
- CVE-2026-48019 — CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay
- CVE-2026-75925 — IXON VPN Client CRLF Injection
- CVE-2026-84962 — Authenticated KMS request forgery via CRLF injection in GCP key identifier strings
- CVE-2026-84379 — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
- CVE-2026-84372 — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
- CVE-2026-82854 — Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
- CVE-2026-82853 — Nodemailer before 8.0.5 SMTP Command Injection via CRLF
- CVE-2026-82661 — Nodemailer CRLF Injection via List-* Header Comments