CVE-2026-42007
largeAuthenticated Use-After-Free in Dovecot Sieve editheader During Mail Delivery
CVE-2026-42007 is a critical (CVSS 3.1: 9.1) use-after-free (CWE-416) in the Sieve editheader mail-editing code that runs during mail delivery, in the Sieve implementation of the Dovecot mail server maintained by Open-Xchange, which assigned the CVE. An attacker who already holds valid mail-account credentials can install or run a Sieve script using the editheader extension so that, while a message is being edited during delivery, memory is freed while still in use and contents beyond the intended buffer are written into the delivered email. This leaks residual memory contents into recipients' mail (reflected in the changed-scope, low confidentiality and integrity scores), can corrupt memory, crash the mail delivery process (high availability impact), and may allow arbitrary code execution in the context of that process. Any deployment running the affected Sieve implementation with the editheader extension enabled and allowing users to manage their own Sieve scripts is exposed; no specific vulnerable or fixed version numbers are stated in the available data. No public proof-of-concept or known in-the-wild exploitation exists (EPSS about 0.3%, not in CISA KEV), but internet-facing mail providers that expose account credentials and permit user-managed filtering are the most plausible targets.
What to do: Upgrade all mail servers running the affected Sieve implementation to the vendor's fixed (non-vulnerable) release cited in the Open-Xchange/Dovecot advisory, since no fixed version numbers are given in this data. As an interim mitigation, disable the Sieve editheader extension as recommended in the advisory and restrict which users can create or modify Sieve scripts. Check delivery logs for delivery-process crashes and delivered messages containing unexpected binary or memory-like content as indicators of attempted exploitation.
| Open-Xchange Dovecot mail server - Sieve implementation (Pigeonhole), editheader extension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.