Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Dovecot

16 known vulnerabilities

5
HIGH
9
MEDIUM
2
LOW

Top Products

dovecot 16
16 CVEs
4.3
CVE-2026-42006

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple

3.1
CVE-2026-40020

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all

5.3
CVE-2026-40016

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits

6.8
CVE-2026-33603

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This

7.4
CVE-2026-27851

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted

3.7
CVE-2026-27860

If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l

5.3
CVE-2026-27859

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma

7.5
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount

4.3
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi

7.4
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u

6.8
CVE-2026-27855

Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern

7.7
CVE-2026-24031

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows

5.3
CVE-2026-0394

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s

7.5
CVE-2025-59032

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi

4.3
CVE-2025-59031

Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen

5.3
CVE-2025-59028

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica

Frequently Asked Questions

How many CVEs affect Dovecot?

Dovecot has 16 CVE records in our database, including 0 critical and 5 high severity vulnerabilities.

What are the most severe Dovecot vulnerabilities?

Dovecot has 0 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Dovecot vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Dovecot products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Dovecot Vulnerabilities

CyberStrike scans your infrastructure for Dovecot vulnerabilities and provides real-time remediation guidance.

Get Started