Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59028

25
FAUCET Score

CVE-2025-59028 describes a Denial of Service (DoS) vulnerability where sending invalid base64 SASL data to a vulnerable server can disconnect the login process, causing all active authentication sessions to fail. Rated as medium severity (CVSS 5.3), this vulnerability can be exploited remotely without authentication and with low complexity to disrupt concurrent logins. There are no known public exploits, Metasploit modules, or Nuclei templates, and it is not present in the CISA KEV catalog, indicating no active exploitation; community discussion is minimal with only one mention.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.3CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
< 3.1.2CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 15th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

freeswitchpatch availablevia llm_extracted
View patch
matrixpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: dovecot (jammy)Fixed in: 1:2.3.16+dfsg1-3ubuntu2.7
ubuntupatch availablevia ubuntu_usn
Product: dovecot (noble)Fixed in: 1:2.3.21+dfsg1-2ubuntu6.3
ubuntupatch availablevia ubuntu_usn
Product: dovecot (questing)Fixed in: 1:2.4.1+dfsg1-5ubuntu4.1

Vendor Advisories (3)

ubuntuUSN-8136-1

Dovecot vulnerabilities

Mar 31, 2026
freeswitchllm-freeswitch-8131297f31fabf91

Invalid base64 authentication can cause DoS for other logins. When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail.

Mar 27, 2026
matrixllm-matrix-a49886e1724573e0

Dovecot vulnerabilities

References

documentation.open-xchange.com / dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
Vendor Advisory