
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59032 is a denial-of-service vulnerability in Dovecot's ManageSieve service caused by improper input validation (CWE-20) when processing the AUTHENTICATE command with a literal as the SASL initial response. The flaw affects Dovecot versions before 2.4.3 and Open-Xchange Dovecot Pro versions before 3.1.3. It was published on March 27, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (OX Advisory, ENISA EUVD).
The root cause is improper input validation (CWE-20) in the ManageSieve AUTHENTICATE command handler. When a client sends a literal string as the SASL initial response — a valid but edge-case protocol construct — the ManageSieve service crashes rather than handling it gracefully. Because the crash can be triggered repeatedly by any unauthenticated network client with access to the ManageSieve port (default TCP 4190), no authentication or user interaction is required. No public technical write-up or proof-of-concept code has been released (OX Advisory, ENISA EUVD).
Successful exploitation causes the ManageSieve service to crash, rendering it unavailable to legitimate users for the duration of the attack — a pure availability impact with no confidentiality or integrity consequences. Because the crash can be triggered repeatedly and requires no authentication, an attacker can sustain a persistent denial-of-service condition against the ManageSieve service. Other Dovecot services (IMAP, POP3) are not directly affected, limiting the blast radius to Sieve script management functionality (OX Advisory, ENISA EUVD).
nmap -sV -p 4190 <target>).{N+}) as the SASL initial response, which the vulnerable code path fails to handle correctly.managesieve process termination entries in /var/log/dovecot.log or syslog); error entries referencing AUTHENTICATE command handling failures.dovecot/managesieve child process as monitored by the Dovecot master process; abnormal process exit codes associated with the ManageSieve worker.The primary remediation is to upgrade Dovecot to version 2.4.3 or later, or Open-Xchange Dovecot Pro to version 3.1.3 or later (OX Advisory). Patches have also been distributed via downstream vendors including Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197, DLA-4556-1), Red Hat (RHSA-2026:13498, RHSA-2026:13830, RHSA-2026:13857, and others), AlmaLinux, Rocky Linux, and openSUSE (Ubuntu Advisory, Debian Announce, Red Hat Errata). If patching cannot be applied immediately, restrict network access to TCP port 4190 to trusted hosts only using firewall rules, or disable the ManageSieve service entirely if it is not required.
The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, generating routine community awareness without significant controversy (oss-sec, Full Disclosure). Downstream Linux distributions responded promptly with security advisories and updated packages. No notable threat actor attribution or significant social media discussion has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."