SASL Authentication Disruption in Dovecot Server by Open-Xchange
CVE-2025-59028
5.3MEDIUM
What is CVE-2025-59028?
A vulnerability exists in Dovecot Server that allows an attacker to send invalid base64 SASL data, which subsequently disconnects the login process from the authentication server. This results in the failure of all active authentication sessions. By exploiting this flaw, an attacker may effectively perform a Denial of Service attack, disrupting concurrent login attempts. Users are advised to upgrade to a fixed version of the software or consider disabling concurrency in their login processes, although this may significantly impact performance, particularly in larger deployments. No public exploits have been reported as of yet.
Affected Version(s)
OX Dovecot Pro 0 <= 3.1.0
OX Dovecot Pro 0 <= 2.4.0
