ZeroHour

Vulnerabilities

43 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-27851
+4 in the same advisory: …40016 …33603 …42006 …40020
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

NVD description · AI analysis pending
9.1
group max
<1%
  • dovecot dovecot
CVE-2026-24031
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

NVD description · AI analysis pending
8.2
group max
<1%
  • dovecot dovecot
CVE-2022-30550
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

NVD description · AI analysis pending
8.82%
  • dovecot dovecot
  • dovecot debian linux
CVE-2021-29157
+2 in the same advisory: …33515 …28200
Dovecot before 2.3.15 allows ../ Path Traversal.

Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

NVD description · AI analysis pending
5.5
group max
<1%
  • dovecot dovecot
  • dovecot fedora
CVE-2020-25275
+1 in the same advisory: …24386
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

NVD description · AI analysis pending
7.5
group max
5%
  • dovecot dovecot
  • dovecot debian linux
  • dovecot fedora
CVE-2020-12674
+2 in the same advisory: …12673 …12100
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

NVD description · AI analysis pending
7.56% PoC
  • dovecot dovecot
  • dovecot debian linux
  • dovecot ubuntu linux
  • +1 more
CVE-2020-10957
+2 in the same advisory: …10967 …10958
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, s

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

NVD description · AI analysis pending
7.5
group max
7% PoC
  • dovecot dovecot
CVE-2020-7046
+1 in the same advisory: …7957
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthentica

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

NVD description · AI analysis pending
7.5
group max
51%
  • dovecot dovecot
  • dovecot fedora
CVE-2019-19722
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Der

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.

NVD description · AI analysis pending
5.32%
  • dovecot dovecot
  • dovecot fedora
CVE-2016-4983
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

NVD description · AI analysis pending
3.3<1% PoC ×2
  • dovecot dovecot
  • dovecot leap
  • dovecot opensuse
  • +1 more
CVE-2019-11500
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

NVD description · AI analysis pending
9.863% PoC
  • dovecot dovecot
  • dovecot pigeonhole
  • dovecot debian linux
  • +1 more
CVE-2019-11499
+1 in the same advisory: …11494
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacce

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

NVD description · AI analysis pending
7.53%
  • dovecot dovecot
  • dovecot fedora
  • dovecot leap
CVE-2019-10691
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 s

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

NVD description · AI analysis pending
7.53%
  • dovecot dovecot
  • dovecot leap
CVE-2019-7524
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to

In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

NVD description · AI analysis pending
7.81%
  • dovecot dovecot
  • dovecot debian linux
  • dovecot ubuntu linux
  • +1 more
CVE-2019-3814
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates.

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

NVD description · AI analysis pending
6.82% PoC
  • dovecot dovecot
  • dovecot ubuntu linux
  • dovecot leap
CVE-2017-2669
Dovecot before version 2.2.29 is vulnerable to a denial of service.

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

NVD description · AI analysis pending
7.54%
  • dovecot dovecot
  • dovecot debian linux
CVE-2017-14461
+1 in the same advisory: …15130
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information dis

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.

NVD description · AI analysis pending
7.1
group max
17%
  • dovecot dovecot
  • dovecot debian linux
  • dovecot ubuntu
CVE-2017-15132
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

NVD description · AI analysis pending
7.53%
  • dovecot dovecot
  • dovecot debian linux
  • dovecot ubuntu linux
CVE-2016-8652
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authenti

The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.

NVD description · AI analysis pending
5.948%
  • dovecot dovecot