CVE-2008-4578medium · CVSS 5.0 — The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized
CVE-2013-6171medium · CVSS 5.8 — checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass a
CVE-2013-2111medium · CVSS 5.0 — The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via
CVE-2019-7524high · CVSS 8.8 — In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b
CVE-2019-10691high · CVSS 7.5 — The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit
CVE-2019-11500critical · CVSS 9.8 — In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This o
CVE-2019-19722medium · CVSS 5.3 — In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because o
CVE-2020-10957high · CVSS 7.5 — In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in
CVE-2020-10958medium · CVSS 5.3 — In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or l
CVE-2020-10967medium · CVSS 5.3 — In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpar
CVE-2020-12100high · CVSS 7.5 — In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour
CVE-2020-12673high · CVSS 7.5 — In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
CVE-2020-12674high · CVSS 7.5 — In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
CVE-2020-25275high · CVSS 7.5 — Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with
CVE-2020-28200medium · CVSS 4.3 — The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular ex
CVE-2021-33515medium · CVSS 4.8 — The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an
CVE-2025-59028medium · CVSS 5.3 — When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai
CVE-2025-59031medium · CVSS 4.3 — Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use
CVE-2025-59032high · CVSS 7.5 — ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeated
CVE-2026-0394medium · CVSS 5.3 — When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added
CVE-2026-24031high · CVSS 7.7 — Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentic
CVE-2026-27855medium · CVSS 6.8 — Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in pa
CVE-2026-27856high · CVSS 7.4 — Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine
CVE-2026-27857medium · CVSS 4.3 — Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client
CVE-2026-27858high · CVSS 7.5 — Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacke
CVE-2026-27859medium · CVSS 5.3 — A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message ca
CVE-2026-27860low · CVSS 3.7 — If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially
CVE-2026-27851high · CVSS 7.4 — When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli
CVE-2026-33603medium · CVSS 6.8 — Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the at
CVE-2026-40016medium · CVSS 5.3 — Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130
CVE-2026-40020low · CVSS 3.1 — Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This c
CVE-2026-42006medium · CVSS 4.3 — An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking on