Improper Handling of Zip Attachments in Dovecot Software
CVE-2025-59031

4.3MEDIUM

Key Information:

Vendor
CVE Published:
27 March 2026

What is CVE-2025-59031?

Dovecot has a vulnerability related to the script used for converting attachments to text, which improperly handles zip-style attachments. This flaw allows an attacker to exploit specially crafted OOXML documents, potentially causing unintended files to be indexed on the system. Consequently, these files may appear in Full-Text Search (FTS) indexes. Users are advised against employing the provided script and are encouraged to utilize safer alternatives such as FTS Tika for file processing to mitigate this risk.

Affected Version(s)

OX Dovecot Pro 0 <= 2.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.