PT-2025-54918 · Fts Tika+4 · Fts Tika+4

CVE-2025-59031

·

Published

2025-01-01

·

Updated

2026-07-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.4.3
Description Dovecot includes a script for converting attachments to text that improperly handles zip-style attachments. An attacker could leverage specially crafted OOXML documents to cause unintended files on the system to be indexed, potentially leading to their inclusion in Full-Text Search (FTS) indexes. The issue relates to the unsafe handling of zip-style attachments during the attachment-to-text conversion process. No publicly available exploits are known at this time.
Recommendations Do not use the provided script for attachment to text conversion. Instead, utilize an alternative solution such as FTS tika.

Exploit

Fix

Allocation of Resources Without Limits

Improper Authentication

Resource Exhaustion

Information Disclosure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-81689
BDU:2026-10384
BDU:2026-10394
BDU:2026-10399
BDU:2026-10400
BDU:2026-10401
BDU:2026-10406
BDU:2026-10407
BDU:2026-10409
CVE-2025-59031
OESA-2026-1849
OPENSUSE-SU-2026:10442-1
OPENSUSE-SU-2026:20554-1
SUSE-SU-2026:1641-1
SUSE-SU-2026:21208-1
USN-8136-1

Affected Products

Dovecot
Fts Tika
Linuxmint
Red Os
Ubuntu