{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2026/cve-2026-27859-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T15:52:09Z",
      "generator": {
        "date": "2026-07-28T15:52:09Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-27859-ELS_OS-RHEL7ELS",
      "initial_release_date": "2026-03-27T09:16:00Z",
      "revision_history": [
        {
          "date": "2026-03-27T09:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T15:52:09Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-27859"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-devel@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-devel@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-mysql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-pigeonhole@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-pgsql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot@2.2.36-8.el7.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-devel@2.2.36-8.el7.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-devel@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-mysql@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-pigeonhole@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-pgsql@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-27859",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available exploits are known.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-27859"
        }
      ],
      "release_date": "2026-03-27T09:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T12:01:19.003626Z",
          "details": "This vulnerability is a DoS-only condition in Dovecot’s LMTP path: a specially crafted email with excessive RFC 2231 parameters can transiently drive high CPU usage during delivery, with no confidentiality or integrity impact. Only hosts that run Dovecot’s LMTP service are exposed; where LMTP is used, it typically sits behind an SMTP MTA that can enforce header/parameter limits before LMTP parses the message. Given the constrained scope, absence of privilege escalation, and no known public exploits, this can be safely deprioritized in centrally managed server/VM environments.",
          "product_ids": [
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}