Dovecot is a widely deployed open-source mail server and IMAP/POP3 daemon that handles email storage and retrieval across many hosting and enterprise environments, despite maintaining a narrow product footprint. The vendor's vulnerability profile clusters around its core mail-server product and the Pigeonhole sieve-filtering extension, with recurring weaknesses in input validation, authentication logic, and resource-consumption handling that reflect the parsing and protocol-state complexity of email-service implementations. The exposure spans a moderate volume of disclosures and carries a meaningful tendency toward serious severity outcomes, though the architectural role—sitting behind authentication boundaries in most deployments—shapes the practical attack surface and remediation priority relative to internet-facing tiers. Defenders should treat Dovecot updates as part of mail-infrastructure patching routines, particularly when input-validation or authentication issues are flagged; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dovecot over time
Signals from CVEs in this vendor scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11500CRITICAL In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishan | Aug 29, 2019 | 9.8 | 67 | NO | NO |
CVE-2020-7046HIGH lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a | Feb 12, 2020 | 7.5 | 53 | NO | NO |
CVE-2016-8652MEDIUM The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setti | Feb 17, 2017 | 5.9 | 38 | NO | NO |
CVE-2026-27851CRITICAL When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can | May 12, 2026 | 9.1 | 35 | NO | NO |
CVE-2017-14461HIGH A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial o | Mar 2, 2018 | 7.1 | 31 | NO | NO |
CVE-2026-42006HIGH An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-24031HIGH Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. | Mar 27, 2026 | 8.2 | 30 | NO | NO |
CVE-2026-27858HIGH Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can force managesieve-login to be unav | Mar 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-59032HIGH ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other user | Mar 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2022-30550HIGH An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect us | Jul 17, 2022 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (69 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dovecot.
Media articles that mention a CVE ID that affects a product developed by Dovecot — matched by CVE ID, not by vendor name.