No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Metrics |
ssvc
|
Tue, 12 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CPU Time Limit Bypass for Sieve Scripts in Open‑Xchange OX Dovecot Pro |
Tue, 12 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known. | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-05-12T15:38:42.912Z
Reserved: 2026-04-08T09:59:59.342Z
Link: CVE-2026-40016
Updated: 2026-05-12T15:38:39.723Z
Status : Awaiting Analysis
Published: 2026-05-12T14:17:03.570
Modified: 2026-05-12T15:08:22.857
Link: CVE-2026-40016
No data.
OpenCVE Enrichment
Updated: 2026-05-12T16:00:12Z