dovecot vulnerabilities
CVEs whose affected-version data names the dovecot package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42006Medium· 4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for clo…
▾ Sunlitdovecot · dovecotEPSS 0.62%via NVD
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authent…
▾ Twilightdovecot · dovecotEPSS 0.41%via NVD