Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Mar 30, 2026 | Mar 27, 2026 |
| Amazon Linux Ami 2 | — | Upgrade dovecot-mysqlUpgrade dovecot-debuginfoUpgrade dovecotUpgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecot-pigeonhole | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade dovecotUpgrade dovecot-pigeonhole-debuginfoUpgrade dovecot-mysqlUpgrade dovecot-debuginfoUpgrade dovecot-mysql-debuginfoUpgrade dovecot-debugsourceUpgrade dovecot-develUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-pgsqlUpgrade dovecot-pigeonhole | Apr 14, 2026 | Mar 27, 2026 |
| Debian | — | Upgrade dovecot | Apr 7, 2026 | Apr 7, 2026 |
| Redhat_linux | — | Upgrade dovecot-pigeonholeUpgrade dovecotUpgrade dovecot-debuginfoUpgrade dovecot-pgsqlNo solution existsUpgrade dovecot-develUpgrade dovecot-mysql | Jun 19, 2026 | Mar 27, 2026 |
| Ubuntu | — | Upgrade dovecot-core | Apr 1, 2026 | Mar 31, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub