Improper Handling of Extra Parameters in Dovecot and OX Dovecot Pro - CVE-2026-27851
Published: May 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to conduct SQL or LDAP injection attacks.
The vulnerability exists due to improper handling of extra parameters in lib-var-expand when using the safe filter with variable expansion. A remote attacker can supply unsafe data that is incorrectly treated as safe to conduct SQL or LDAP injection attacks.
This can occur when the vulnerable behavior is used in authentication.
Affected software
OX Dovecot Pro
Debian Linux
Ubuntu
Fedora
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot
How to mitigate CVE-2026-27851
OX Dovecot Pro - update to 3.1.5
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot - addressed in versions 2.4.4-1.fc43, 2.4.4-1.fc44