Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27857

28
FAUCET Score

CVE-2026-27857 is a denial-of-service vulnerability where sending a specially crafted "NOOP" command with numerous parentheses causes excessive memory allocation, potentially leading to process termination. The specific affected products are not detailed in the provided information. Rated as medium severity (CVSS 4.3), this vulnerability is a low-complexity network attack requiring low privileges, primarily impacting availability by allowing an attacker to exhaust memory resources. There are no known public exploits, Metasploit modules, or Nuclei templates, and it is not listed on the CISA KEV catalog. Active exploitation has not been observed, and community discussion regarding this CVE is minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.3CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
< 2.3.22.1CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
>= 3.0.0, < 3.0.5CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
>= 3.1.0, < 3.1.4CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.67%
Probability of exploitation in next 30 days
EPSS Percentile
48.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0067 is in the 24th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

freeswitchpatch availablevia llm_extracted
View patch
matrixpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: dovecot (jammy)Fixed in: 1:2.3.16+dfsg1-3ubuntu2.7
ubuntupatch availablevia ubuntu_usn
Product: dovecot (noble)Fixed in: 1:2.3.21+dfsg1-2ubuntu6.3
ubuntupatch availablevia ubuntu_usn
Product: dovecot (questing)Fixed in: 1:2.4.1+dfsg1-5ubuntu4.1

Vendor Advisories (3)

ubuntuUSN-8136-1

Dovecot vulnerabilities

Mar 31, 2026
freeswitchllm-freeswitch-b4169a527106fd0f

imap-login: Excessive memory usage DoS. Sending `NOOP (((...)))` command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections.

Mar 27, 2026
matrixllm-matrix-a49886e1724573e0

Dovecot vulnerabilities

References

access.redhat.com / errata/RHSA-2026:13498
access.redhat.com / errata/RHSA-2026:13830
access.redhat.com / errata/RHSA-2026:13857
access.redhat.com / errata/RHSA-2026:17602
access.redhat.com / errata/RHSA-2026:17625
access.redhat.com / errata/RHSA-2026:17626
access.redhat.com / errata/RHSA-2026:17628
access.redhat.com / errata/RHSA-2026:17630
access.redhat.com / errata/RHSA-2026:18053
access.redhat.com / errata/RHSA-2026:19149
access.redhat.com / errata/RHSA-2026:19364
access.redhat.com / errata/RHSA-2026:19453
access.redhat.com / errata/RHSA-2026:19455
access.redhat.com / errata/RHSA-2026:26564
access.redhat.com / security/cve/CVE-2026-27857
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27857.json
documentation.open-xchange.com / dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
Vendor Advisory