CVE-2026-27851

NameCVE-2026-27851
DescriptionWhen safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1136444

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)bullseye1:2.3.13+dfsg1-2+deb11u1fixed
bullseye (security)1:2.3.13+dfsg1-2+deb11u3fixed
bookworm1:2.3.19.1+dfsg1-2.1+deb12u5fixed
bookworm (security)1:2.3.19.1+dfsg1-2.1+deb12u6fixed
trixie1:2.4.1+dfsg1-6+deb13u5vulnerable
trixie (security)1:2.4.1+dfsg1-6+deb13u6fixed
forky, sid1:2.4.4+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcebullseye(not affected)
dovecotsourcebookworm(not affected)
dovecotsourcetrixie1:2.4.1+dfsg1-6+deb13u6
dovecotsource(unstable)1:2.4.4+dfsg1-11136444

Notes

[bookworm] - dovecot <not-affected> (Vulnerable code introduced later)
[bullseye] - dovecot <not-affected> (Vulnerable code introduced later)
https://www.openwall.com/lists/oss-security/2026/05/12/6
Fixed by: https://github.com/dovecot/core/commit/d75c04e8ccbeb70d66d05938665fe145175ac1b5 (2.4.4)

Search for package or bug name: Reporting problems