CVEFinder.io

CVE-2025-59032

âš ī¸ high
🔍 Scan for this CVE
Summary

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS Score
7.5
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-03-27
First Seen: 2026-03-28
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 69.1% of all 321,566 vulnerabilities in our database.

#99,499
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Mar 27, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-04-30
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-27851 âš ī¸ high 7.4 0.0 When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted... 2026-05-12
CVE-2026-33603 đŸ”ļ medium 6.8 0.0 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This ... 2026-05-12
CVE-2026-40016 đŸ”ļ medium 5.3 0.0 Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ... 2026-05-12
CVE-2026-40020 â„šī¸ low 3.1 0.0 Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all... 2026-05-12
CVE-2026-42006 đŸ”ļ medium 4.3 0.0 An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple... 2026-05-12
CVE-2025-59028 đŸ”ļ medium 5.3 0.1 When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica... 2026-03-27
These CVEs affect the same products