Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-33603 Details

Description

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-99Improper Control of Resource Identifiers ('Resource Injection')[email protected]

Affected Products

ProductVersions
dovecot dovecot
< 2.4.4

CPE

  • cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
open-xchange dovecot
< 3.1.5

CPE

  • cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-33603
NVD Published Date:
May 12, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2026-33603 Details - Not Deferred