CVE-2026-40017
Deferred Deferred - Pending Action

IMAP THREAD Hash Collision CPU Exhaustion

Vulnerability report for CVE-2026-40017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: Open-Xchange

Description

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-18
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open-xchange ox_imap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to send a specially crafted email that causes the IMAP THREAD command to use excessive CPU resources. The attack exploits hash table collisions in message headers, leading to performance degradation or denial of service for IMAP services.

Detection Guidance

Monitor system for abnormal CPU usage during IMAP operations. Check for processes consuming excessive CPU when THREAD commands are issued. No specific commands are provided in the context.

Impact Analysis

It can cause high CPU usage on the mail server, slowing down or crashing IMAP services. Users may experience delays or inability to access emails. The server may become unresponsive, affecting all users relying on IMAP for email access.

Compliance Impact

This vulnerability causes denial of service for IMAP services by consuming excessive CPU resources, which could lead to service unavailability. For GDPR, this may impact the availability of personal data processing systems, potentially violating Article 32 requirements for security and integrity. For HIPAA, it could disrupt access to protected health information, affecting the availability requirement under the Security Rule.

Mitigation Strategies

Kill the offending process causing high CPU usage. Remove the malicious message from the affected mailbox. Update to a non-vulnerable version of the IMAP service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart