CVE-2025-59032 PUBLISHED

Assigner: OX
Reserved: 08.09.2025 Published: 27.03.2026 Updated: 27.03.2026

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Open-Xchange GmbH
Product OX Dovecot Pro
Versions Default: unaffected
  • affected from 0 to 3.1.0 (incl.)
  • affected from 0 to 2.4.0 (incl.)

References

Problem Types

  • Improper Input Validation cwe