CVE-2025-59028 describes a Denial of Service (DoS) vulnerability where sending invalid base64 SASL data to a vulnerable server can disconnect the login process, causing all active authentication sessions to fail. Rated as medium severity (CVSS 5.3), this vulnerability can be exploited remotely without authentication and with low complexity to disrupt concurrent logins. There are no known public exploits, Metasploit modules, or Nuclei templates, and it is not present in the CISA KEV catalog, indicating no active exploitation; community discussion is minimal with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.3CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* | ||
< 3.1.2CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Dovecot vulnerabilities
Mar 31, 2026Invalid base64 authentication can cause DoS for other logins. When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail.
Mar 27, 2026Dovecot vulnerabilities