SASL Authentication Disruption in Dovecot Server by Open-Xchange
CVE-2025-59028

5.3MEDIUM

Key Information:

Vendor
CVE Published:
27 March 2026

What is CVE-2025-59028?

A vulnerability exists in Dovecot Server that allows an attacker to send invalid base64 SASL data, which subsequently disconnects the login process from the authentication server. This results in the failure of all active authentication sessions. By exploiting this flaw, an attacker may effectively perform a Denial of Service attack, disrupting concurrent login attempts. Users are advised to upgrade to a fixed version of the software or consider disabling concurrency in their login processes, although this may significantly impact performance, particularly in larger deployments. No public exploits have been reported as of yet.

Affected Version(s)

OX Dovecot Pro 0 <= 3.1.0

OX Dovecot Pro 0 <= 2.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.