« Volver al listado

Dovecot

Dovecot: vulnerabilidades y CVE

Dovecot tiene 84 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE84
Últimos 12 meses28
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73208Alta (7.4)0.31%—28 ago 2026
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the…
CVE-2026-52687Media (6.5)0.40%—28 ago 2026
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the…
CVE-2026-42393Baja (3.1)0.17%—28 ago 2026
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make…
CVE-2026-42391Alta (7.5)0.45%—28 ago 2026
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the…
CVE-2026-42008Media (4.3)0.24%—28 ago 2026
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any…
CVE-2026-42007Crítica (9.1)0.34%—28 ago 2026
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the…
CVE-2026-40019Media (5.9)0.38%—28 ago 2026
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script…
CVE-2026-40013Media (4.3)0.87%—28 ago 2026
An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption…
CVE-2026-33606Media (4.8)0.25%—28 ago 2026
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can…
CVE-2026-33604Media (5.9)0.31%—28 ago 2026
An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message…
CVE-2026-33263Media (4.3)0.55%—28 ago 2026
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community…
CVE-2026-42006Media (4.3)0.82%—12 may 2026
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular,…
CVE-2026-40020Media (4.3)0.29%—12 may 2026
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able…
CVE-2026-40016Media (6.5)0.43%—12 may 2026
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server…
CVE-2026-33603Media (5.3)0.23%—12 may 2026
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If…
CVE-2026-27851Crítica (9.1)0.57%—12 may 2026
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks…
CVE-2026-27860Media (5.3)0.34%—27 mar 2026
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out…
CVE-2026-27859Media (5.3)0.40%—27 mar 2026
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA…
CVE-2026-27858Alta (7.5)1.0%—27 mar 2026
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the…
CVE-2026-27857Alta (7.5)0.80%—27 mar 2026
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not…
CVE-2026-27856Media (5.9)0.43%—27 mar 2026
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full…
CVE-2026-27855Media (5.9)0.39%—27 mar 2026
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An…
CVE-2026-24031Alta (8.2)0.40%—27 mar 2026
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If…
CVE-2026-0394Media (5.3)0.43%—27 mar 2026
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is…
CVE-2025-59032Alta (7.5)0.70%—27 mar 2026
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port,…
CVE-2025-59031Media (4.3)0.28%—27 mar 2026
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to…
CVE-2025-59028Alta (7.5)0.45%—27 mar 2026
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break…
CVE-2025-30189Alta (7.4)0.54%—31 oct 2025
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same…
CVE-2024-23185Alta (7.5)1.3%—10 sept 2024
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building…
CVE-2024-23184Media (5)0.84%—10 sept 2024
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1059 Command and Scripting Interpreter1
  3. T1078 Valid Accounts1
  4. T1210 Exploitation of Remote Services1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Dovecot