CVE-2025-59032High· 7.5▾ TwilightManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the ser…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
dovecot < 2.4.3dovecot < 3.1.3Upgrade past the affected range:
dovecot 3.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59028Medium· 5.3When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail
CVE-2025-59031Medium· 4.3Dovecot has provided a script to use for attachment to text conversion
CVE-2026-42006Medium· 4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped
CVE-2025-48612High· 7.8In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper input validation
CVE-2025-48601Medium· 5.5In multiple locations, there is a possible permanent denial of service due to improper input validation