Products: 2
    Vulnerabilities: 69
    Known Exploited: 0
    1
    Critical Level Threats
    21
    High Level Threats
    41
    Medium Level Threats
    6
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-42006

    An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

    Last Modified: Aug 14, 2026
    Published: May 12, 2026

    CVE-2026-40020

    Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.

    Last Modified: May 18, 2026
    Published: May 12, 2026

    CVE-2026-40016

    CPU Time Limit Bypass for Sieve Scripts in Open‑Xchange OX Dovecot Pro

    Last Modified: May 18, 2026
    Published: May 12, 2026

    CVE-2026-33603

    Fake SCRAM TLS Channel Binding Allows MITM Eavesdropping in OX Dovecot Pro

    Last Modified: May 18, 2026
    Published: May 12, 2026

    CVE-2026-27851

    When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

    Last Modified: Aug 14, 2026
    Published: May 12, 2026
    Items Per Page
    Dovecot Vulnerabilities & Security CVEs | CVE-DB