dovecot has 2 CVEs on record. The median CVSS is 5.8 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped41CVE-2026-42006Medium· 4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP24
dovecot vulnerabilities
CVEs affecting dovecot, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-42006Medium· 4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for clo…
▾ Sunlitdovecot · dovecotEPSS 0.62%via NVD
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authent…
▾ Twilightdovecot · dovecotEPSS 0.41%via NVD