Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dovecot

First CVE: Apr 25, 2007Active for: 19 yearsTotal CVEs: 69
39.5
VTI Score
Medium

Dovecot is a widely deployed open-source mail server and IMAP/POP3 daemon that handles email storage and retrieval across many hosting and enterprise environments, despite maintaining a narrow product footprint. The vendor's vulnerability profile clusters around its core mail-server product and the Pigeonhole sieve-filtering extension, with recurring weaknesses in input validation, authentication logic, and resource-consumption handling that reflect the parsing and protocol-state complexity of email-service implementations. The exposure spans a moderate volume of disclosures and carries a meaningful tendency toward serious severity outcomes, though the architectural role—sitting behind authentication boundaries in most deployments—shapes the practical attack surface and remediation priority relative to internet-facing tiers. Defenders should treat Dovecot updates as part of mail-infrastructure patching routines, particularly when input-validation or authentication issues are flagged; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
69
Total CVEs
More Total CVEs than 99% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dovecot over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2007
19 years ago
Most Recent CVE
May 12, 2026
73 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11500CRITICAL
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishan
Aug 29, 20199.867NONO
CVE-2020-7046HIGH
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a
Feb 12, 20207.553NONO
CVE-2016-8652MEDIUM
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setti
Feb 17, 20175.938NONO
CVE-2026-27851CRITICAL
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can
May 12, 20269.135NONO
CVE-2017-14461HIGH
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial o
Mar 2, 20187.131NONO
CVE-2026-42006HIGH
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still
May 12, 20267.530NONO
CVE-2026-24031HIGH
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration.
Mar 27, 20268.230NONO
CVE-2026-27858HIGH
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unav
Mar 27, 20267.529NONO
CVE-2025-59032HIGH
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other user
Mar 27, 20267.529NONO
CVE-2022-30550HIGH
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect us
Jul 17, 20228.829NONO
View all 69 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products69 CVEs
61%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (5.8%)
Network41 (59.4%)
Unknown23 (33.3%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low37 (53.6%)
High9 (13.0%)
Unknown23 (33.3%)
User Interaction
None46 (66.7%)
Unknown23 (33.3%)
Required0 (0.0%)
Privileges Required
Low12 (17.4%)
High0 (0.0%)
None34 (49.3%)
Unknown23 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dovecot.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dovecot — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dovecot's Products

View all 4 CNAs →

Top CWEs