Dovecot
Vendor:
First CVE: Mar 27, 2026 · Active for under a year
16
Total CVEs
More Total CVEs than 92% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dovecot over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2026
3 months ago
Most Recent CVE
May 12, 2026
75 days ago
CVE Severity & Scoring
Dovecot16 CVEs
56%
38%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low13 (81.3%)
High3 (18.8%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (18.8%)
High0 (0.0%)
None13 (81.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27851CRITICAL When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can | May 12, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-42006HIGH An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-24031HIGH Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. | Mar 27, 2026 | 8.2 | 30 | NO | NO |
CVE-2026-27858HIGH Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can force managesieve-login to be unav | Mar 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-59032HIGH ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other user | Mar 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-27857HIGH Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left all | Mar 27, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-40016MEDIUM Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker | May 12, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-59028HIGH When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to Do | Mar 27, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-27856MEDIUM Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring ou | Mar 27, 2026 | 5.9 | 23 | NO | NO |
CVE-2026-33603MEDIUM Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself betwee | May 12, 2026 | 5.3 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Dovecot
Top CWEs
Versions
No cataloged versions.