CVE-2026-40203
Received Received - Intake

IMAP Compression Information Leak in Open-Xchange

Vulnerability report for CVE-2026-40203, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: Open-Xchange

Description

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves IMAP compression in email sessions. When enabled, the same compression state is reused across responses, causing response sizes to depend on both attacker-supplied mail and other mail in the mailbox. An attacker can observe IMAP traffic sizes to confirm if a small message body matches a guessed text, potentially disclosing secret-like content.

Detection Guidance

This vulnerability is related to IMAP compression and requires observing IMAP traffic sizes. Detection involves monitoring IMAP session traffic patterns and compression behavior. No specific commands are provided in the context.

Impact Analysis

An attacker could use this vulnerability to infer the content of sensitive emails by analyzing the size of IMAP traffic. This could lead to disclosure of confidential information, such as passwords or private messages, even though full recovery of arbitrary content was not demonstrated.

Mitigation Strategies

Disable IMAP compression immediately. Update to a non-vulnerable version of the IMAP server software. Monitor for unusual IMAP traffic patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40203. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart