
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59031 is an information disclosure vulnerability in Dovecot's attachment-to-text conversion script that unsafely handles zip-style attachments. Attackers can send specially crafted OOXML documents to cause unintended system files to be indexed and exposed through Full Text Search (FTS) indexes. The vulnerability affects Dovecot before version 2.4.3, Open-Xchange Dovecot Pro before 2.3.22.1, and OX Dovecot Pro 3.0.0–3.1.3 (before 3.1.3). It was published on March 27, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium), classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (OX Advisory, ENISA EUVD).
The root cause is unsafe handling of zip-style archive attachments in Dovecot's bundled attachment-to-text conversion script, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). OOXML documents (e.g., .docx, .xlsx) are ZIP-based archives, and the conversion script fails to properly restrict which files within or referenced by the archive are processed. An authenticated attacker can craft a malicious OOXML document and submit it via email; when the script processes the attachment, it may traverse to or include unintended files on the server filesystem, causing those files to be indexed into the FTS backend. Exploitation requires low privileges (authenticated network access) and no user interaction beyond the server processing the attachment (OX Advisory, oss-sec).
Successful exploitation allows authenticated attackers to cause arbitrary, unintended files on the Dovecot server's filesystem to be indexed into FTS indexes, potentially exposing sensitive system or application data that would not normally be accessible through mail search. The confidentiality impact is limited (CVSS C:L), with no integrity or availability impact. While lateral movement is not directly enabled, exposure of configuration files, credentials, or other sensitive data via FTS search results could facilitate further attacks (OX Advisory, ENISA EUVD).
SEARCH TEXT) against the mailbox to retrieve content from the unintended indexed files, potentially exposing sensitive server-side data (OX Advisory, oss-sec)./etc/, /var/, application config paths) during indexing operations.SEARCH TEXT queries that return content not expected from normal email bodies, potentially indicating FTS result harvesting.The primary remediation is to upgrade Dovecot to version 2.4.3 or later; for Open-Xchange Dovecot Pro, upgrade to 2.3.22.1 (for 2.x) or 3.1.3 (for 3.0.0+). As an immediate workaround, stop using the Dovecot-provided attachment-to-text conversion script entirely and replace it with a safer alternative such as Apache Tika via the FTS Tika plugin. Administrators should audit their FTS configuration to confirm which conversion scripts are in use and disable the vulnerable script until patching is complete (OX Advisory, Ubuntu USN-8136-1, openSUSE Advisory).
The vulnerability was disclosed via the oss-security mailing list and Dovecot's official Open-Xchange security advisory channel. Multiple Linux distributions including Ubuntu, Debian, and openSUSE issued security advisories and updated packages in response. Coverage has been primarily technical and low-key, consistent with the medium severity rating and absence of active exploitation (oss-sec, Ubuntu USN-8136-1, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."