CVE-2024-23184 - CVE House
Back to Database
Status published Medium CVE-2024-23184

Having a large number of address headers (From, To, Cc,...

Vulnerability Description

Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23184

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Open-Xchange GmbH

View all reports →

Affected Software

OX Dovecot Pro
Vulnerable Versions:
0

Timeline

Official Publish: September 10th, 2024
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Weaknesses (CWE)