Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-8136-1 | Dovecot vulnerabilities |
Thu, 30 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dovecot
Dovecot dovecot Open-xchange dovecot |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
|
| Vendors & Products |
Dovecot
Dovecot dovecot Open-xchange dovecot |
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Pro |
Sat, 28 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Invalid Base64 SASL in OX Dovecot Pro | dovecot: Dovecot: Denial of Service via invalid SASL data |
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Invalid Base64 SASL in OX Dovecot Pro |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T19:43:08.685Z
Reserved: 2025-09-08T14:22:28.105Z
Link: CVE-2025-59028
Updated: 2026-03-27T19:43:04.020Z
Status : Analyzed
Published: 2026-03-27T09:16:18.620
Modified: 2026-04-30T17:50:06.170
Link: CVE-2025-59028
OpenCVE Enrichment
Updated: 2026-05-02T00:45:30Z
Ubuntu USN