Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use-After-Free in OX Dovecot Sieve Editheader Extension Allows Potential Code Execution |
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known. | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-08-28T10:30:52.428Z
Reserved: 2026-04-23T11:15:21.199Z
Link: CVE-2026-42007
No data.
Status : Received
Published: 2026-08-28T12:16:29.260
Modified: 2026-08-28T12:16:29.260
Link: CVE-2026-42007
No data.
OpenCVE Enrichment
Updated: 2026-08-28T14:30:08Z
-
CWE-416
Use After Free