<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Dovecot (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/dovecot.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dovecot-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Dovecot (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-24031 – Dovecot SQL based authentication can be bypassed when auth_username_chars is cle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24031</guid>
    <pubDate>Fri, 27 Mar 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24031</strong></p>
  <p>Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23185 – Very large headers can cause resource exhaustion when parsing message. The messa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23185</guid>
    <pubDate>Tue, 10 Sep 2024 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23185</strong></p>
  <p>Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single lon…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34108 – mailcow is a mail server suite based on Dovecot, Postfix and other open source s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34108</guid>
    <pubDate>Wed, 07 Jun 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34108</strong></p>
  <p>mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using specially crafted passwords during the authentication process. The issue arises from the behavior of the `passwd-verify.lua` s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26490 – mailcow is a dockerized email package, with multiple containers linked in one br...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26490</guid>
    <pubDate>Sat, 04 Mar 2023 00:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26490</strong></p>
  <p>mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse this vulnerability to obtain shell access to the Docker container running dovecot. The imapsync Perl script implements all…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30550 – An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30550</guid>
    <pubDate>Sun, 17 Jul 2022 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30550</strong></p>
  <p>An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configuration…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29157 – Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29157</guid>
    <pubDate>Mon, 28 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29157</strong></p>
  <p>Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25275 – Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, lead...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25275</guid>
    <pubDate>Mon, 04 Jan 2021 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25275</strong></p>
  <p>Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26102 – In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26102</guid>
    <pubDate>Fri, 25 Sep 2020 06:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26102</strong></p>
  <p>In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12674 – In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12674</guid>
    <pubDate>Wed, 12 Aug 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12674</strong></p>
  <p>In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12673 – In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will cras...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12673</guid>
    <pubDate>Wed, 12 Aug 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12673</strong></p>
  <p>In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12100 – In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12100</guid>
    <pubDate>Wed, 12 Aug 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12100</strong></p>
  <p>In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10957 – In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10957</guid>
    <pubDate>Mon, 18 May 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10957</strong></p>
  <p>In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7046 – lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7046</guid>
    <pubDate>Wed, 12 Feb 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7046</strong></p>
  <p>lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11500 – In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11500</guid>
    <pubDate>Thu, 29 Aug 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11500</strong></p>
  <p>In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11494 – In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11494</guid>
    <pubDate>Wed, 08 May 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11494</strong></p>
  <p>In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11499 – In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login compon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11499</guid>
    <pubDate>Wed, 08 May 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11499</strong></p>
  <p>In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10691 – The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10691</guid>
    <pubDate>Wed, 24 Apr 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10691</strong></p>
  <p>The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7524 – In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7524</guid>
    <pubDate>Thu, 28 Mar 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7524</strong></p>
  <p>In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3814 – It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3814</guid>
    <pubDate>Wed, 27 Mar 2019 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3814</strong></p>
  <p>It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15132 – A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15132</guid>
    <pubDate>Thu, 25 Jan 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15132</strong></p>
  <p>A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3235 – Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3235</guid>
    <pubDate>Thu, 17 Sep 2009 10:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3235</strong></p>
  <p>Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-263…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4577 – The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4577</guid>
    <pubDate>Wed, 15 Oct 2008 20:08:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4577</strong></p>
  <p>The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4577">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
