CVE-2025-59028

MEDIUM

OX Dovecot Pro < 2.4.0 and < 3.1.0 - Denial of Service via Invalid BASE64 SASL Data

Title source: llm
STIX 2.1

Description

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (4)
dovecot/dovecot < 2.4.3
open-xchange/dovecot < 3.1.2
Open-Xchange GmbH/OX Dovecot Pro < 2.4.0
Open-Xchange GmbH/OX Dovecot Pro < 3.1.0
Published Mar 27, 2026
Tracked Since Mar 27, 2026