Known vulnerabilities in dovecot (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:dovecot_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 19
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting dovecot (Red Hat package) dovecot (Red Hat package) is affected by 19 known vulnerabilities: 1 high, 16 medium, 2 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131869 - Resource exhaustion
CVE-2026-42006
CWE-400 Low
No
No
2.2.36-8.el7_9.2, 2.3.8-9.el8_4.2, 2.3.16-2.el8_6.2, 2.3.16-3.el8_8.2, 2.3.16-8.el9_2.3, 2.3.16-11.el9_4.3, 2.3.16-15.el9_6.2, 2.3.21-16.el10_0.2, 2.3.21-19.el10_2.1 19.05.2026 SB2026051937
SB2026051938
SB2026051939
and 14 more
#VU124722 - Improper input validation
CVE-2025-59032
CWE-20 Medium
No
No
2.2.36-8.el7_9.1, 2.3.8-9.el8_4.1, 2.3.16-2.el8_6.1, 2.3.16-3.el9_0.1, 2.3.16-7.el8_10, 2.3.16-8.el9_2.2, 2.3.16-11.el9_4.2, 2.3.16-15.el9_6.1, 2.3.16-15.el9_7.1, 2.3.21-16.el10_0.1, 2.3.21-16.el10_1.1 01.04.2026 SB2026040128
SB2026040132
SB2026041137
and 14 more
#VU124728 - Resource exhaustion
CVE-2026-27857
CWE-400 Medium
No
No
2.2.36-8.el7_9.1, 2.3.8-9.el8_4.1, 2.3.16-2.el8_6.1, 2.3.16-3.el9_0.1, 2.3.16-7.el8_10, 2.3.16-8.el9_2.2, 2.3.16-11.el9_4.2, 2.3.16-15.el9_6.1, 2.3.16-15.el9_7.1, 2.3.21-16.el10_0.1, 2.3.21-16.el10_1.1 01.04.2026 SB2026040129
SB2026040132
SB2026041137
and 20 more
#VU124729 - Resource exhaustion
CVE-2026-27858
CWE-400 Medium
No
No
2.2.36-8.el7_9.1, 2.3.8-9.el8_4.1, 2.3.16-2.el8_6.1, 2.3.16-3.el9_0.1, 2.3.16-7.el8_10, 2.3.16-8.el9_2.2, 2.3.16-11.el9_4.2, 2.3.16-15.el9_6.1, 2.3.16-15.el9_7.1, 2.3.21-16.el10_0.1, 2.3.21-16.el10_1.1 01.04.2026 SB2026040129
SB2026040132
SB2026041137
and 16 more
#VU124730 - Improper Authentication
CVE-2026-27856
CWE-287 High
No
No
2.2.36-8.el7_9.1 01.04.2026 SB2026040129
SB2026040132
SB2026041137
and 3 more
#VU96022 - Resource exhaustion
CVE-2024-23184
CWE-400 Medium
No
No
2.3.16-6.el8_10, 2.3.16-8.el9_2.1, 2.3.16-11.el9_4.1 14.08.2024 SB2024081482
SB2024081536
SB2024082002
and 11 more
#VU96021 - Resource exhaustion
CVE-2024-23185
CWE-400 Medium
No
No
2.3.16-6.el8_10, 2.3.16-8.el9_2.1, 2.3.16-11.el9_4.1 14.08.2024 SB2024081482
SB2024081536
SB2024082002
and 11 more
#VU65119 - Permissions, Privileges, and Access Controls
CVE-2022-30550
CWE-264 Medium
No
No
2.3.16-3.el8, 2.3.16-7.el9 11.07.2022 SB2022071169
SB2022071171
SB2022071911
and 10 more
#VU54286 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-33515
CWE-74 Medium
No
No
2.3.16-2.el8 21.06.2021 SB2021062107
SB2021062223
SB2021071801
and 12 more
#VU49238 - Improper input validation
CVE-2020-25275
CWE-20 Medium
No
No
2.3.8-9.el8 04.01.2021 SB2021010411
SB2021010412
SB2021010418
and 9 more
#VU49237 - Exposure of sensitive information to an unauthorized actor
CVE-2020-24386
CWE-200 Medium
No
No
2.3.8-9.el8 04.01.2021 SB2021010411
SB2021010412
SB2021010418
and 11 more
#VU45673 - Improper input validation
CVE-2020-12674
CWE-20 Medium
No
No
2.2.36-5.el8_0.3, 2.2.36-6.el7_8.1, 2.2.36-10.el8_1.2, 2.3.8-2.el8_2.2 13.08.2020 SB2020081309
SB2020081310
SB2020082104
and 15 more
#VU45672 - Out-of-bounds read
CVE-2020-12673
CWE-125 Medium
No
No
2.2.36-5.el8_0.3, 2.2.36-6.el7_8.1, 2.2.36-10.el8_1.2, 2.3.8-2.el8_2.2 13.08.2020 SB2020081309
SB2020081310
SB2020082104
and 15 more
#VU45671 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-12100
CWE-835 Medium
No
No
2.2.36-5.el8_0.3, 2.2.36-6.el7_8.1, 2.2.36-10.el8_1.2, 2.3.8-2.el8_2.2 13.08.2020 SB2020081309
SB2020081310
SB2020081917
and 16 more
#VU27984 - Improper input validation
CVE-2020-10967
CWE-20 Medium
No
No
2.3.8-4.el8 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 11 more
#VU27983 - Use After Free
CVE-2020-10958
CWE-416 Medium
No
No
2.3.8-4.el8 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 8 more
#VU27981 - NULL Pointer Dereference
CVE-2020-10957
CWE-476 Medium
No
No
2.3.8-2.el8_2.1 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 8 more
#VU18089 - Stack-based buffer overflow
CVE-2019-7524
CWE-121 Low
No
No
2.2.36-6.el7 28.03.2019 SB2019032801
SB2019032901
SB2019040102
and 10 more
#VU17374 - Authentication Bypass Issues
CVE-2019-3814
CWE-592 Medium
No
No
2.2.36-6.el7 05.02.2019 SB2019020504
SB2019020615
SB2019020616
and 9 more