ManageSieve Service Crash Vulnerability in Open-Xchange Dovecot
CVE-2025-59032

7.5HIGH

Key Information:

Vendor
CVE Published:
27 March 2026

What is CVE-2025-59032?

A vulnerability in Open-Xchange's Dovecot affects the ManageSieve service, leading to a crash when the AUTHENTICATE command is executed with a literal as the SASL initial response. This issue can be exploited to repeatedly crash the ManageSieve service, resulting in denial of service for legitimate users. To mitigate this risk, it is recommended to control access to the ManageSieve port or disable the service if it is not in use. Users are also advised to upgrade to a patched version to ensure service continuity.

Affected Version(s)

OX Dovecot Pro 0 <= 3.1.0

OX Dovecot Pro 0 <= 2.4.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.