Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:rpm/redhat/dovecot

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-42006 is a vulnerability in the Dovecot IMAP server that allows an attacker to cause uncontrolled memory usage by sending excessive bracing characters over IMAP. The previous fix for a related issue was incomplete, leaving a bypass via open braces. This can lead to memory consumption up to the configured memory limit, resulting in a denial of service. No public exploits are known. Red Hat has released security updates addressing this issue for multiple versions of Red Hat Enterprise Linux and related products.

Join the discussion
0

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (CVE-2025-59032) * dovecot: denial of service via crafted message before authentication (CVE-2026-27858) * dovecot: denial of service via specially crafted NOOP command (CVE-2026-27857) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (CVE-2025-59032) * dovecot: denial of service via crafted message before authentication (CVE-2026-27858) * dovecot: denial of service via specially crafted NOOP command (CVE-2026-27857) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Multiple denial of service vulnerabilities have been identified in Dovecot, an IMAP and POP3 server for Linux and UNIX-like systems. These include a crafted SASL initial response in the AUTHENTICATE command affecting ManageSieve (CVE-2025-59032), a crafted message before authentication (CVE-2026-27858), and a specially crafted NOOP command (CVE-2026-27857). These vulnerabilities could allow an attacker to cause denial of service conditions. Red Hat has issued a security update addressing these issues in Dovecot packages for Red Hat Enterprise Linux 9.2 and related variants.

Join the discussion
0

Multiple denial of service vulnerabilities have been identified in Dovecot, an IMAP and POP3 server for Linux and UNIX-like systems. These include a denial of service via a crafted SASL initial response in the AUTHENTICATE command (CVE-2025-59032), denial of service via a crafted message before authentication (CVE-2026-27858), and denial of service via a specially crafted NOOP command (CVE-2026-27857). Red Hat has issued a security advisory providing updates to address these issues in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The vulnerabilities are rated with high severity by Red Hat Product Security. No CVSS scores are provided in the advisory. The update is available for affected Red Hat Enterprise Linux 9.0 packages.

Join the discussion
0

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (CVE-2025-59032) * dovecot: denial of service via crafted message before authentication (CVE-2026-27858) * dovecot: denial of service via specially crafted NOOP command (CVE-2026-27857) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Two vulnerabilities in Dovecot, an IMAP and POP3 server, can lead to denial of service or resource exhaustion. CVE-2024-23184 involves triggering denial of service by using a large number of address headers. CVE-2024-23185 involves resource exhaustion caused by very large headers during message parsing. These issues affect Red Hat Enterprise Linux 9 and related variants. A security update addressing these vulnerabilities is available from Red Hat.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:rpm/redhat/dovecot
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses