| Name | CVE-2026-40203 |
| Description | When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6526-1 |
| Debian Bugs | 1146018 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| dovecot (PTS) | bookworm, bookworm (security) | 1:2.3.19.1+dfsg1-2.1+deb12u6 | vulnerable |
| trixie | 1:2.4.1+dfsg1-6+deb13u6 | vulnerable | |
| trixie (security) | 1:2.4.1+dfsg1-6+deb13u7 | fixed | |
| forky | 1:2.4.5+dfsg1-2 | fixed | |
| sid | 1:2.4.5+dfsg1-3 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| dovecot | source | trixie | 1:2.4.1+dfsg1-6+deb13u7 | DSA-6526-1 | ||
| dovecot | source | (unstable) | 1:2.4.5+dfsg1-1 | 1146018 |
https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
Fixed by: https://github.com/dovecot/core/commit/34787cb86a0147d987ab821772d310faab048ba6
Fixed by: https://github.com/dovecot/core/commit/c7d4e41586ac8049839529ab20f36c6fbb485112
Fixed by: https://github.com/dovecot/core/commit/34c2a1e6b2373afcf0e11e7a1387aced82669b9d
Fixed by: https://github.com/dovecot/core/commit/dd2cd9fec90267ed9b34e93a46a26b36fbbb457f