CVE-2026-33604
Received Received - Intake

Dovecot SMTP Smuggling via Message Body Crafted Line Endings

Vulnerability report for CVE-2026-33604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: Open-Xchange

Description

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in message data. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dovecot dovecot *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-655 The product has a protection mechanism that is too difficult or inconvenient to use, encouraging non-malicious users to disable or bypass the mechanism, whether by accident or on purpose.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to bypass Dovecot's outbound protection by crafting a message with a specific line ending. If a downstream mail server is vulnerable to SMTP smuggling, it may interpret part of the message body as SMTP commands, enabling email spoofing. It is similar to CVE-2023-51764 and CVE-2023-51766.

Detection Guidance

Detecting this vulnerability requires checking Dovecot configurations and message handling. Look for misconfigured Sieve redirect or submission relay settings that allow crafted line endings. Inspect mail logs for unusual SMTP command injection attempts or bare carriage returns in message data.

Impact Analysis

An attacker could send spoofed emails that appear to come from your domain, potentially tricking recipients into disclosing sensitive information or installing malware. If you control receiving mail servers, ensure they reject bare carriage returns in message data to mitigate this risk.

Mitigation Strategies

Update Dovecot to a non-vulnerable version immediately. Ensure receiving mail servers reject bare carriage returns in message data. Review and restrict Sieve redirect and submission relay configurations to prevent crafted line endings from being processed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart