یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
کم EPSS 0.3% اولویت 17/100

CVE-2026-27860— CVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.

Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how to report bugs.Below is the list of all security holes found from Dovecot. Note that most of these are quite minor holes2026-03-27T00:00:00.000ZCVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.2026-03-27T00:00:00.000ZCVE-2026-27859: v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU…

انتشار: 2026-03-27 00:00 آخرین مشاهده داده: 2026-08-28 15:25 1 منبع · 1 رسمیاعتماد متوسط · 48/100
اولویت VulnWatch 17/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS — / 0.3% شدت فنی / احتمال بهره‌برداری
کیفیت داده 50/100 نیازمند توجه · اعتماد متوسط
تازگی داده قدیمی قدیمی‌تر از ۳۰ روز · 1 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
EPSS 0.3%سیگنال EPSS پایین‌تر است؛ سایر شاخص‌ها را نیز در تصمیم لحاظ کنید.
کیفیت داده 50/100نیازمند توجه · 1 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار ساختاریافته هنوز ثبت نشده است؛ مراجع اصلی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority9
سیگنال فوریت اضافی ثبت نشده است.
01

خلاصه آسیب‌پذیری

Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how to report bugs.Below is the list of all security holes found from Dovecot. Note that most of these are quite minor holes2026-03-27T00:00:00.000ZCVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.2026-03-27T00:00:00.000ZCVE-2026-27859: v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU…
02

توضیحات کامل

Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how to report bugs.Below is the list of all security holes found from Dovecot. Note that most of these are quite minor holes2026-03-27T00:00:00.000ZCVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.2026-03-27T00:00:00.000ZCVE-2026-27859: v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU usage. A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU.2026-03-27T00:00:00.000ZCVE-2026-27858: managesieve-login out-of-memory DoS. Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.2026-03-27T00:00:00.000ZCVE-2026-27857: imap-login: Excessive memory usage DoS. Sending `NOOP (((...)))` command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections.2026-03-27T00:00:00.000ZCVE-2026-27856: doveadm: Credentials verified without timing safety. Doveadm credentials are ve
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
در اطلاعات دریافت‌شده هنوز راهکار مشخصی ثبت نشده است.
در اطلاعات دریافت‌شده دستور اجرایی مشخصی پیدا نشد. برای بررسی کامل راهکار، منبع اصلی را باز کنید.
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
48/100
اعتماد متوسط اعتماد داده 50/100 نیازمند توجه داده قدیمی وضعیت تازگی قدیمی‌تر از ۳۰ روز تازگی مشاهده 75/100 کامل‌بودن · مناسب 52/100 پوشش منابع 1 منبع مرتبط 1 رسمی · 1 سطح ۱ 1 اختلاف بین منابع 2 خلأ کیفیت
اختلاف بین منابع دیده شد

اختلاف‌ها مخفی نمی‌شوند و در شاخص اعتماد نیز اثر کاهشی دارند. پیش از تصمیم عملیاتی، مقدار هر منبع را بررسی کنید.

شدت
unknownlow
Dovecot Security رسمی
CVSS
—
شدت
unknown
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-03-27
Dovecot Security رسمی
CVSS
—
شدت
low
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-03-27
Dovecot Security رسمی
CVSS
—
شدت
low
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-03-27
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
توضیحات 3 منبع
Dovecot Securityرسمی
2026-03-27T00:00:00.000ZCVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.
منبع ↗
Dovecot Securityرسمی
Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how to report bugs.Below is the list of all se...
منبع ↗
Dovecot Securityرسمی
DownloadDocumentationPigeonholeSupportSecurityMailing listSecurity ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more...
منبع ↗
شدت 3 منبع
Dovecot Securityرسمی
unknown
منبع ↗
Dovecot Securityرسمی
low
منبع ↗
Dovecot Securityرسمی
low
منبع ↗
خلاصه 3 منبع
Dovecot Securityرسمی
2026-03-27T00:00:00.000ZCVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.
منبع ↗
Dovecot Securityرسمی
Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how to report bugs.Below is the list of all se...
منبع ↗
Dovecot Securityرسمی
DownloadDocumentationPigeonholeSupportSecurityMailing listSecurity ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more...
منبع ↗
عنوان 3 منبع
Dovecot Securityرسمی
CVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.
منبع ↗
Dovecot Securityرسمی
bugreport-mail
منبع ↗
Dovecot Securityرسمی
https://github.com/dovecot/website
منبع ↗
↗