CVE-2020-14145medium · CVSS 5.9 — The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This a
CVE-2021-28041high · CVSS 7.1 — ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket ac
CVE-2016-20012medium · CVSS 5.3 — OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH s
CVE-2021-41617high · CVSS 7.0 — sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplement
CVE-2021-36368low · CVSS 3.7 — An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=v
CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2023-48795medium · CVSS 5.9 — The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
CVE-2023-51385medium · CVSS 6.5 — In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is refere
CVE-2023-51767high · CVSS 7.0 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer val
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2025-32728medium · CVSS 4.3 — In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent
CVE-2026-35385high · CVSS 7.5 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the
CVE-2026-35387low · CVSS 3.1 — OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgo
CVE-2026-35388low · CVSS 2.5 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35414medium · CVSS 4.2 — OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a
CVE-2026-59995medium · CVSS 4.2 — sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker
CVE-2026-59996medium · CVSS 4.2 — scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destina
CVE-2026-59997medium · CVSS 4.2 — internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-l
CVE-2026-59998medium · CVSS 4.8 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windo
CVE-2026-59999medium · CVSS 5.9 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-60000low · CVSS 3.7 — sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempt
CVE-2026-60001medium · CVSS 6.5 — sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60002high · CVSS 7.7 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only
CVE-2008-4578medium · CVSS 5.0 — The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized
CVE-2013-6171medium · CVSS 5.8 — checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass a
CVE-2013-2111medium · CVSS 5.0 — The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via
CVE-2019-7524high · CVSS 8.8 — In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b
CVE-2019-10691high · CVSS 7.5 — The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit
CVE-2019-11500critical · CVSS 9.8 — In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This o
CVE-2019-19722medium · CVSS 5.3 — In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because o
CVE-2020-10957high · CVSS 7.5 — In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in
CVE-2020-10958medium · CVSS 5.3 — In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or l
CVE-2020-10967medium · CVSS 5.3 — In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpar
CVE-2020-12100high · CVSS 7.5 — In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour
CVE-2020-12673high · CVSS 7.5 — In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
CVE-2020-12674high · CVSS 7.5 — In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
CVE-2020-25275high · CVSS 7.5 — Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with
CVE-2020-28200medium · CVSS 4.3 — The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular ex
CVE-2021-33515medium · CVSS 4.8 — The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an
CVE-2025-59028medium · CVSS 5.3 — When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai
CVE-2025-59031medium · CVSS 4.3 — Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use
CVE-2025-59032high · CVSS 7.5 — ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeated
CVE-2026-0394medium · CVSS 5.3 — When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added
CVE-2026-24031high · CVSS 7.7 — Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentic
CVE-2026-27855medium · CVSS 6.8 — Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in pa
CVE-2026-27856high · CVSS 7.4 — Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine
CVE-2026-27857medium · CVSS 4.3 — Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client
CVE-2026-27858high · CVSS 7.5 — Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacke
CVE-2026-27859medium · CVSS 5.3 — A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message ca
CVE-2026-27860low · CVSS 3.7 — If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially