{"apiVersion":"1.0","identifier":"CVE-2026-40203","description":"When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user-s IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.","publishedAt":"2026-08-28T12:16:28","lastModifiedAt":"2026-08-28T16:17:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40203","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","epssProbability":0,"riskScore":0.37,"affectedProduct":"dovecot","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-40203","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-40203","en":"https://www.redsauce.net/en/cves/CVE-2026-40203","fr":"https://www.redsauce.net/fr/cves/CVE-2026-40203","pt":"https://www.redsauce.net/pt/cves/CVE-2026-40203","de":"https://www.redsauce.net/de/cves/CVE-2026-40203","sk":"https://www.redsauce.net/sk/cves/CVE-2026-40203","el":"https://www.redsauce.net/el/cves/CVE-2026-40203"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-40203"}}