CVE-2025-59032
published 2026-03-27CVE-2025-59032: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.70%
48.9th percentile
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) | dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) |
| dovecot | dovecot | < 2.4.3 | 2.4.3 |
| dovecot | dovecot | >= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u2 | 1:2.3.19.1+dfsg1-2.1+deb12u2 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-6+deb13u4 | 1:2.4.1+dfsg1-6+deb13u4 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.7 | 1:2.3.16+dfsg1-3ubuntu2.7 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6.3 | 1:2.3.21+dfsg1-2ubuntu6.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-5ubuntu4.1 | 1:2.4.1+dfsg1-5ubuntu4.1 |
| open-xchange | dovecot | < 3.1.3 | 3.1.3 |
| open-xchange_gmbh | ox_dovecot_pro | <= 3.1.0 | — |
| ubuntu | dovecot | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2026-04-28·CVSS 5.3
CVE-2026-0394 [MEDIUM] Dovecot regression
Title: Dovecot regression
Summary: USN-8136-1 introduced a regression in Dovecot
USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this i
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 5.3
CVE-2026-27857 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. Thi
Red Hat
dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
vendor_redhat·2026-03-27·CVSS 7.5
CVE-2025-59032 [HIGH] CWE-229 dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
A flaw was found in ManageSieve. A remote attacker can exploit this vulnerability by sending a crafted SASL (Simple Authentication and Security Layer) initial response during the AUTHENTICATE command. This can cause the ManageSieve service to crash repeatedly, leading to a Denial of Service (DoS) for other users.
Package: dovecot (Red Hat Enterprise L
Debian
CVE-2025-59032: dovecot - ManageSieve AUTHENTICATE command crashes when using literal as SASL initial resp...
vendor_debian·2025·CVSS 7.5
CVE-2025-59032 [HIGH] CVE-2025-59032: dovecot - ManageSieve AUTHENTICATE command crashes when using literal as SASL initial resp...
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
Scope: local
bookworm: resolved (fixed in 1:2.3.19.1+dfsg1-2.1+deb12u2)
bullseye: open
forky: open
sid: resolved (fixed in 1:2.4.3+dfsg1-1)
trixie: resolved (fixed in 1:2.4.1+dfsg1-6+deb13u4)
OSV
dovecot vulnerabilities
osv·2026-03-31·CVSS 5.3
CVE-2025-59028 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was dis
OSV
CVE-2025-59032: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response
osv·2026-03-27·CVSS 7.5
CVE-2025-59032 [HIGH] CVE-2025-59032: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
GHSA
GHSA-w2gj-cmfm-c4j4: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response
ghsa_unreviewed·2026-03-27
CVE-2025-59032 [HIGH] CWE-20 GHSA-w2gj-cmfm-c4j4: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-59032 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-59032 [HIGH] CVE-2025-59032 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59032 :
Dovecot vulnerability analysis and mitigation
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
Source : NVD
## 7.5
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Dovecot
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
dovecot
dovecot-devel
Sources
N
Bugzilla
CVE-2025-59032 dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
bugzilla·2026-03-27·CVSS 7.5
CVE-2025-59032 [HIGH] CVE-2025-59032 dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
CVE-2025-59032 dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.
https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.jsonhttps://access.redhat.com/errata/RHSA-2026:13498https://access.redhat.com/errata/RHSA-2026:13830https://access.redhat.com/errata/RHSA-2026:13857https://access.redhat.com/errata/RHSA-2026:17602https://access.redhat.com/errata/RHSA-2026:17625https://access.redhat.com/errata/RHSA-2026:17626https://access.redhat.com/errata/RHSA-2026:17628https://access.redhat.com/errata/RHSA-2026:17630https://access.redhat.com/errata/RHSA-2026:18053https://access.redhat.com/errata/RHSA-2026:19149https://access.redhat.com/errata/RHSA-2026:19364https://access.redhat.com/errata/RHSA-2026:19453https://access.redhat.com/errata/RHSA-2026:19455https://access.redhat.com/errata/RHSA-2026:26564https://access.redhat.com/security/cve/CVE-2025-59032https://bugzilla.redhat.com/show_bug.cgi?id=2452172https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59032.json
2026-03-27
Published