Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98277.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98277
Upstream
  • CVE-2026-42392
Published
2026-08-28T12:16:29Z
Modified
2026-09-03T05:28:38Z
Summary
CVE-2026-42392 affecting package dovecot 2.3.20-1
Details

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known.

References

Affected packages

Azure Linux:3 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/azure-linux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.20-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98277.json"