Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86805.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86805
Upstream
Published
2026-05-12T14:17:03Z
Modified
2026-09-20T05:32:18Z
Summary
CVE-2026-40016 affecting package dovecot 2.3.20-1
Details

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.

References

Affected packages

Azure Linux:3 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/azure-linux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.3.20-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86805.json"