CVE-2025-59028Medium· 5.3▾ SunlitWhen sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
dovecot < 2.4.3dovecot < 3.1.2Upgrade past the affected range:
dovecot 3.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59032High· 7.5ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response
CVE-2025-59031Medium· 4.3Dovecot has provided a script to use for attachment to text conversion
CVE-2026-42006Medium· 4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped
CVE-2025-48612High· 7.8In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper input validation
CVE-2025-48601Medium· 5.5In multiple locations, there is a possible permanent denial of service due to improper input validation