A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Ce Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Ce Open-xchange ox Dovecot Pro |
Tue, 01 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Null Byte Crash in Trusted Proxy Forwarding Causing Denial of Service in OX Dovecot | dovecot: Dovecot: Denial of Service via NUL byte in forwarding information |
| Weaknesses | CWE-170 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 28 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Null Byte Crash in Trusted Proxy Forwarding Causing Denial of Service in OX Dovecot |
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known. | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published: 2026-08-28T10:12:29.710Z
Updated: 2026-08-28T15:53:43.599Z
Reserved: 2026-04-27T08:53:58.839Z
Link: CVE-2026-42395
Updated: 2026-08-28T14:32:29.220Z
Status : Deferred
Published: 2026-08-28T12:16:29.887
Modified: 2026-09-03T18:13:44.643
Link: CVE-2026-42395