Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Mar 30, 2026 | Mar 27, 2026 |
| Amazon Linux Ami 2 | — | Upgrade dovecot-develUpgrade dovecot-pgsqlUpgrade dovecot-pigeonholeUpgrade dovecot-debuginfoUpgrade dovecot-mysqlUpgrade dovecot | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade dovecot-mysql-debuginfoUpgrade dovecot-debuginfoUpgrade dovecot-debugsourceUpgrade dovecot-pigeonhole-debuginfoUpgrade dovecotUpgrade dovecot-mysqlUpgrade dovecot-develUpgrade dovecot-pgsql-debuginfoUpgrade dovecot-pigeonholeUpgrade dovecot-pgsql | Apr 14, 2026 | Mar 27, 2026 |
| Debian | — | Upgrade dovecot | Apr 7, 2026 | Apr 7, 2026 |
| Redhat_linux | — | Upgrade dovecot-pgsqlUpgrade dovecot-mysqlUpgrade dovecot-develNo solution existsUpgrade dovecot-pigeonholeUpgrade dovecot-debuginfoUpgrade dovecot | Jun 19, 2026 | Mar 27, 2026 |
| Ubuntu | — | Upgrade dovecot-core | Apr 1, 2026 | Mar 31, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub