{"id":"CVE-2025-59028","title":"When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail","summary":"When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-20"],"vendor":"dovecot","product":"dovecot","affected":["dovecot < 2.4.3","dovecot < 3.1.2"],"patched":["dovecot 3.1.2"],"published":"2026-03-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59028","references":[{"url":"https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json","label":"security@open-xchange.com"}],"tags":["nvd"],"epss":0.00447,"epssPercentile":0.36475,"ingestedAt":"2026-09-30T22:27:27.741Z","slug":"CVE-2025-59028","body":"## Overview\n\nWhen sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.\n\n## Affected\n\n- `dovecot < 2.4.3`\n- `dovecot < 3.1.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `dovecot 3.1.2`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}