Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98274.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98274
Upstream
  • CVE-2026-40203
Published
2026-08-28T12:16:28Z
Modified
2026-09-03T05:28:38Z
Summary
CVE-2026-40203 affecting package dovecot 2.3.20-1
Details

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

References

Affected packages

Azure Linux:3 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/azure-linux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.20-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98274.json"