| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-73209 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can send crafted compressed dat ... |
| CVE-2026-73208 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that holds a token intended for a different purpose can au ... |
| CVE-2026-52687 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can select a compression algori ... |
| CVE-2026-52681 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | Sieve CPU resource usage is tracked in the compiled script, so an atta ... |
| CVE-2026-42395 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | A host listed as a trusted proxy can send forwarding information conta ... |
| CVE-2026-42393 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | The comparison used for the doveadm password and API key is not fully ... |
| CVE-2026-42392 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can send an invalid IMAP URLFET ... |
| CVE-2026-42391 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An unauthenticated attacker can send an IMAP ID command with a very la ... |
| CVE-2026-42008 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | Forwarding information received from a host listed as a trusted proxy ... |
| CVE-2026-42007 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can use a Sieve script with the ... |
| CVE-2026-40205 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that holds an OAuth2 token granting only part of the requi ... |
| CVE-2026-40204 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | None None None No publicly available exploits are known. |
| CVE-2026-40203 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | When IMAP compression is enabled, the same compression state is reused ... |
| CVE-2026-40019 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An unauthenticated attacker can send a truncated quoted argument to th ... |
| CVE-2026-40018 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | None None None No publicly available exploits are known. |
| CVE-2026-40017 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that can send mail to a user can craft a message header wh ... |
| CVE-2026-40016 | vulnerable (no DSA, ignored) | fixed | fixed | fixed | fixed | Attacker can upload a malicious Sieve script over ManageSieve service ... |
| CVE-2026-40015 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can open many connections to th ... |
| CVE-2026-40014 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that can send mail to a user can craft a message header th ... |
| CVE-2026-40013 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can submit a Sieve script conta ... |
| CVE-2026-33607 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that has valid credentials can use IMAP LIST command to co ... |
| CVE-2026-33606 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | Mail content stored by a user can be crafted so that it is interpreted ... |
| CVE-2026-33605 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An unauthenticated attacker can crash the ManageSieve login process by ... |
| CVE-2026-33604 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that can get Dovecot to relay a message, for example throu ... |
| CVE-2026-33263 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | When mail_max_userip_connections is set (default 10) and reached, subm ... |
| CVE-2026-27852 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that can send mail to a user can craft a message whose hea ... |
| CVE-2020-28200 | vulnerable (no DSA, ignored) | fixed | fixed | fixed | fixed | The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource ... |
| Bug | Description |
|---|
| CVE-2026-42006 | An attacker can cause uncontrolled memory usage with excessive bracing ... |
| CVE-2026-40020 | Attacker can use the IMAP SETACL command to inject the anyone permissi ... |
| CVE-2026-33603 | Attacker can use a specially crafted base64 exchange between Dovecot a ... |
| CVE-2026-27860 | If auth_username_chars is empty, it is possible to inject arbitrary LD ... |
| CVE-2026-27859 | A mail message containing excessive amount of RFC 2231 MIME parameters ... |
| CVE-2026-27858 | Attacker can send a specifically crafted message before authentication ... |
| CVE-2026-27857 | Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ... |
| CVE-2026-27856 | Doveadm credentials are verified using direct comparison which is susc ... |
| CVE-2026-27855 | Dovecot OTP authentication is vulnerable to replay attack under specif ... |
| CVE-2026-27851 | When safe filter is used with variable expansion, all following pipeli ... |
| CVE-2026-24031 | Dovecot SQL based authentication can be bypassed when auth_username_ch ... |
| CVE-2026-0394 | When dovecot has been configured to use per-domain passwd files, and t ... |
| CVE-2025-59032 | ManageSieve AUTHENTICATE command crashes when using literal as SASL in ... |
| CVE-2025-59031 | Dovecot has provided a script to use for attachment to text conversion ... |
| CVE-2025-59028 | When sending invalid base64 SASL data, login process is disconnected f ... |
| CVE-2025-30189 | When cache is enabled, some passdb/userdb drivers incorrectly cache al ... |
| CVE-2024-23185 | Very large headers can cause resource exhaustion when parsing message. ... |
| CVE-2024-23184 | Having a large number of address headers (From, To, Cc, Bcc, etc.) bec ... |
| CVE-2022-30550 | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 b ... |
| CVE-2021-33515 | The submission service in Dovecot before 2.3.15 allows STARTTLS comman ... |
| CVE-2021-29157 | Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with acce ... |
| CVE-2020-25275 | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and ... |
| CVE-2020-24386 | An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, ... |
| CVE-2020-12674 | In Dovecot before 2.3.11.3, sending a specially formatted RPA request ... |
| CVE-2020-12673 | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request ... |
| CVE-2020-12100 | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp ... |
| CVE-2020-10967 | In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash ... |
| CVE-2020-10958 | In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an un ... |
| CVE-2020-10957 | In Dovecot before 2.3.10.1, unauthenticated sending of malformed param ... |
| CVE-2020-7957 | The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle ... |
| CVE-2020-7046 | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 ... |
| CVE-2019-19722 | In Dovecot before 2.3.9.2, an attacker can crash a push-notification d ... |
| CVE-2019-11500 | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole be ... |
| CVE-2019-11499 | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-lo ... |
| CVE-2019-11494 | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-lo ... |
| CVE-2019-10691 | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeate ... |
| CVE-2019-7524 | In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker ... |
| CVE-2019-3814 | It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 in ... |
| CVE-2017-15132 | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SA ... |
| CVE-2017-15130 | A denial of service flaw was found in dovecot before 2.2.34. An attack ... |
| CVE-2017-14461 | A specially crafted email delivered over SMTP and passed on to Dovecot ... |
| CVE-2017-2669 | Dovecot before version 2.2.29 is vulnerable to a denial of service. Wh ... |
| CVE-2016-8652 | The auth component in Dovecot before 2.2.27, when auth-policy is confi ... |
| CVE-2016-4983 | A postinstall script in the dovecot rpm allows local users to read the ... |
| CVE-2015-3420 | The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 ... |
| CVE-2014-3430 | Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x befo ... |
| CVE-2013-6171 | checkpassword-reply in Dovecot before 2.2.7 performs setuid operations ... |
| CVE-2013-2111 | The IMAP functionality in Dovecot before 2.2.2 allows remote attackers ... |
| CVE-2011-4318 | Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ... |
| CVE-2011-2167 | script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ... |
| CVE-2011-2166 | script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ... |
| CVE-2011-1929 | lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2. ... |
| CVE-2010-4011 | Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memor ... |
| CVE-2010-3780 | Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause ... |
| CVE-2010-3779 | Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admi ... |
| CVE-2010-3707 | plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0 ... |
| CVE-2010-3706 | plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0 ... |
| CVE-2010-3304 | The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to ... |
| CVE-2010-0745 | Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote ... |
| CVE-2010-0535 | Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled ... |
| CVE-2009-3897 | Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of ce ... |
| CVE-2009-3235 | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1 ... |
| CVE-2009-2632 | Buffer overflow in the SIEVE script component (sieve/script.c), as use ... |
| CVE-2008-5301 | Directory traversal vulnerability in the ManageSieve implementation in ... |
| CVE-2008-4907 | The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the ... |
| CVE-2008-4578 | The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass inte ... |
| CVE-2008-4577 | The ACL plugin in Dovecot before 1.1.4 treats negative access rights a ... |
| CVE-2008-1218 | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1 ... |
| CVE-2008-1199 | Dovecot before 1.0.11, when configured to use mail_extra_groups to all ... |
| CVE-2007-6598 | Dovecot before 1.0.10, with certain configuration options including us ... |
| CVE-2007-4211 | The ACL plugin in Dovecot before 1.0.3 allows remote authenticated use ... |
| CVE-2007-2231 | Directory traversal vulnerability in index/mbox/mbox-storage.c in Dove ... |
| CVE-2006-5973 | Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and ... |
| CVE-2006-2414 | Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows r ... |
| CVE-2006-0730 | Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow ... |