CVE detail
CVE-2026-27858
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 29.4 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
18 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27858.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 27, 2026, 9:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2452175bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/security/cve/CVE-2026-27858access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:26564access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:19455access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:19453access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:19364access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:19149access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:18053access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:17630access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:17628access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:17626access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:17625access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:17602access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:13857access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:13830access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:13498access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 27, 2026, 9:16 AM - https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.jsondocumentation.open-xchange.com
No excerpt available.
Vendor Advisorydocumentation.open-xchange.comMar 27, 2026, 9:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42006CVSS 4.3 · Medium
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still…
- CVE-2026-27857CVSS 4.3 · Medium
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left al…
- CVE-2026-40016CVSS 5.3 · Medium
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker…
- CVE-2026-27859CVSS 5.3 · Medium
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume l…
- CVE-2026-67437CVSS 7.5 · High
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login hand…
- CVE-2026-63119CVSS 6.2 · Medium
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp ge…