CVE-2025-59028
published 2026-03-27CVE-2025-59028: When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.45%
36.0th percentile
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.4.3+dfsg1-1 (sid) | dovecot 1:2.4.3+dfsg1-1 (sid) |
| dovecot | dovecot | < 2.4.3 | 2.4.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-6+deb13u4 | 1:2.4.1+dfsg1-6+deb13u4 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.7 | 1:2.3.16+dfsg1-3ubuntu2.7 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6.3 | 1:2.3.21+dfsg1-2ubuntu6.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-5ubuntu4.1 | 1:2.4.1+dfsg1-5ubuntu4.1 |
| open-xchange | dovecot | < 3.1.2 | 3.1.2 |
| open-xchange_gmbh | ox_dovecot_pro | <= 3.1.0 | — |
| ubuntu | dovecot | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2026-04-28·CVSS 5.3
CVE-2026-0394 [MEDIUM] Dovecot regression
Title: Dovecot regression
Summary: USN-8136-1 introduced a regression in Dovecot
USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this i
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 5.3
CVE-2026-27857 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. Thi
Red Hat
dovecot: Dovecot: Denial of Service via invalid SASL data
vendor_redhat·2026-03-27·CVSS 5.3
CVE-2025-59028 [MEDIUM] CWE-1286 dovecot: Dovecot: Denial of Service via invalid SASL data
dovecot: Dovecot: Denial of Service via invalid SASL data
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
A flaw was found in Dovecot. A remote attacker can exploit this vulnerability by sending invalid base64 Simple Authentication and Security Layer (SASL) data to the server. This action disconnects the login process from the authentication server, causing all active authentication sessions to fail. Consequently, this can lead to a Denial of Service (DoS)
Debian
CVE-2025-59028: dovecot - When sending invalid base64 SASL data, login process is disconnected from the au...
vendor_debian·2025·CVSS 5.3
CVE-2025-59028 [MEDIUM] CVE-2025-59028: dovecot - When sending invalid base64 SASL data, login process is disconnected from the au...
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Scope: local
bookworm: resolved
bullseye: resolved
forky: open
sid: resolved (fixed in 1:2.4.3+dfsg1-1)
trixie: resolved (fixed in 1:2.4.1+dfsg1-6+deb13u4)
VulDB
Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0 improper authentication (adv-2026-0001 / Nessus ID 304143)
vuldb·2026-05-06·CVSS 7.5
CVE-2025-59028 [HIGH] Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0 improper authentication (adv-2026-0001 / Nessus ID 304143)
A vulnerability identified as critical has been detected in Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0. This affects an unknown function. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2025-59028. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
OSV
dovecot vulnerabilities
osv·2026-03-31·CVSS 5.3
CVE-2025-59028 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was dis
GHSA
GHSA-9q9x-wwfr-fxqm: When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail
ghsa_unreviewed·2026-03-27
CVE-2025-59028 [MEDIUM] CWE-20 GHSA-9q9x-wwfr-fxqm: When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
OSV
CVE-2025-59028: When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail
osv·2026-03-27·CVSS 5.3
CVE-2025-59028 [MEDIUM] CVE-2025-59028: When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-59028 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-59028 [MEDIUM] CVE-2025-59028 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59028 :
Dovecot vulnerability analysis and mitigation
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Source : NVD
## 5.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Dovecot
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 27
Exploitation Probability (EPSS) 0.1
Affected packages and librar
Bugzilla
CVE-2025-59028 dovecot: Dovecot: Denial of Service via invalid SASL data
bugzilla·2026-03-27·CVSS 7.5
CVE-2025-59028 [HIGH] CVE-2025-59028 dovecot: Dovecot: Denial of Service via invalid SASL data
CVE-2025-59028 dovecot: Dovecot: Denial of Service via invalid SASL data
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
2026-03-27
Published