CVE-2026-73209
Deferred Deferred - Pending Action

Stack Overflow in Open-Xchange IMAP Service

Vulnerability report for CVE-2026-73209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: Open-Xchange

Description

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open-xchange imaps *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker with valid credentials to send specially crafted compressed data to a vulnerable IMAP service. This causes the service to exhaust its stack memory and crash, terminating the process. The result is a degradation or complete denial of service for IMAP functionality.

Detection Guidance

Monitor IMAP service logs for crashes or stack exhaustion errors. Check for repeated connection terminations or service degradation. Use network monitoring tools to detect unusual compressed data patterns sent to IMAP ports.

Impact Analysis

If you run a vulnerable IMAP service, an attacker could disrupt email access for users, leading to service outages or reduced performance. Users may be unable to send or receive emails until the service is restarted.

Compliance Impact

This vulnerability causes denial of service by crashing the IMAP service, which could disrupt access to sensitive data. While not directly violating GDPR or HIPAA, such disruptions may impact data availability and integrity requirements under these regulations.

Mitigation Strategies

Update the affected Open-Xchange IMAP service to a non-vulnerable version to prevent the stack exhaustion and process termination. Monitor system logs for crashes in the IMAP service as an indicator of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart