# CVE-2026-73209

## Summary

- **CVE ID:** CVE-2026-73209
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-674
- **Published:** Aug 28, 2026
- **Last Modified:** Aug 28, 2026

## Description

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.

## Affected Products

- Open-Xchange GmbH — OX Dovecot Pro (2.3.0)
- Open-Xchange GmbH — OX Dovecot Pro (3.0.0)
- Open-Xchange GmbH — OX Dovecot Pro (3.1.0)
- Open-Xchange GmbH — OX Dovecot CE (2.3.0)

## References

- [CNA](https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0003.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._