cbcvebase.
CVE-2025-30189
published 2025-10-31

CVE-2025-30189: When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users…

PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.55%
42.1th percentile
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.4.1+dfsg1-7 (forky)dovecot 1:2.4.1+dfsg1-7 (forky)
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-6+deb13u11:2.4.1+dfsg1-6+deb13u1
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-71:2.4.1+dfsg1-7
open-xchange_gmbhox_dovecot_pro<= 3.1.0

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.