PT-2026-83069 · Dovecot · Dovecot

·

CVE-2026-42393

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description The comparison process for the doveadm password and API key is not fully timing safe. This allows an attacker on the same network as the doveadm service to determine the length of the configured secret by making repeated requests and measuring response timing. While the secret value itself is not disclosed, knowing its length reduces the effort required to guess it.
Recommendations Update to version 2.4.5-1.1. Restrict network access to the doveadm service to trusted clients.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98310
CVE-2026-42393
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot