CVE-2026-27857
DOCUMENTATION: A flaw was found in dovecot. An unauthenticated and remote attacker can send a specially crafted "NOOP" command containing numerous open and close parentheses without a command-ending line feed, causing the server to allocate an excessive amount of memory, resulting in a denial of service.
STATEMENT: This flaw allows an unauthenticated and remote attacker to cause a denial of service via a specially crafted "NOOP" command. Due to this reason, this vulnerability has been rated with an important severity.
MITIGATION: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-27857
