CVE detail
CVE-2026-42006
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:46532access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:46381access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:46380access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:46379access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:44373access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:44357access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:44355access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:42091access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:41988access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:41905access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42006.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 12, 2026, 2:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2476476bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 12, 2026, 2:17 PM - https://access.redhat.com/security/cve/CVE-2026-42006access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 12, 2026, 2:17 PM - https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.jsondocumentation.open-xchange.com
No excerpt available.
Vendor Advisorydocumentation.open-xchange.comMay 12, 2026, 2:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-27858CVSS 7.5 · High
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be una…
- CVE-2026-27857CVSS 4.3 · Medium
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left al…
- CVE-2026-40016CVSS 5.3 · Medium
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker…
- CVE-2026-27859CVSS 5.3 · Medium
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume l…
- CVE-2026-67437CVSS 7.5 · High
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login hand…
- CVE-2026-63119CVSS 6.2 · Medium
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp ge…