It was discovered that Dovecot incorrectly treated some variable expansion pipelines as safe in authentication filters. An attacker could possibly use this issue to perform SQL or LDAP injection attacks. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-27851)
It was discovered that Dovecot incorrectly verified SCRAM TLS channel binding in certain base64 exchanges. A remote attacker could possibly use this issue to obtain sensitive information in a machine-in-the-middle attack. (CVE-2026-33603)
It was discovered that Dovecot incorrectly enforced Sieve script CPU limits. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-40016)
It was discovered that Dovecot incorrectly handled certain IMAP SETACL commands. An attacker could possibly use this issue to spam folders to other users. (CVE-2026-40020)
It was discovered that Dovecot incorrectly handled excessive IMAP bracing. An attacker could possibly use this issue to cause Dovecot to use excessive resources, leading to a denial of service. (CVE-2026-42006)
1:2.3.16+dfsg1-3ubuntu2.91:2.3.21+dfsg1-2ubuntu6.51:2.4.1+dfsg1-5ubuntu4.21:2.4.2+dfsg1-3ubuntu2.1