Direct Vulnerabilities

Known vulnerabilities in the dovecot package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2026-33603

<2.4.4-r0
  • C
CVE-2026-27851

<2.4.4-r0
  • M
CVE-2026-40020

<2.4.4-r0
  • M
CVE-2026-40016

<2.4.4-r0
  • L
CVE-2026-42006

<2.4.4-r0
  • L
CVE-2026-27859

<2.4.3-r0
  • M
CVE-2026-27856

<2.4.3-r0
  • H
CVE-2026-24031

<2.4.3-r0
  • H
CVE-2026-27857

<2.4.3-r0
  • M
CVE-2026-27860

<2.4.3-r0
  • H
CVE-2025-59028

<2.4.3-r0
  • M
CVE-2026-27855

<2.4.3-r0
  • L
CVE-2025-59031

<2.4.3-r0
  • L
CVE-2025-30189

<2.4.2-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.3.9.3-r0
  • H
CVE-2019-10691

<2.3.6-r0
  • M
Arbitrary Command Injection

<2.3.15-r0
  • C
Out-of-bounds Write

<2.3.7.2-r0
  • M
Directory Traversal

<2.3.15-r0
  • H
CVE-2019-11499

<2.3.6-r0
  • M
Improper Input Validation

<2.3.9.3-r0
  • M
NULL Pointer Dereference

<2.3.9.2-r0
  • M
Improper Certificate Validation

<2.3.4.1-r0
  • L
CVE-2024-23185

<2.3.21.1-r0
  • H
Uncontrolled Recursion

<2.3.11.3-r0
  • H
Out-of-bounds Read

<2.3.11.3-r0
  • H
CVE-2019-11494

<2.3.6-r0
  • H
Improper Authentication

<2.3.19.1-r5
  • M
Resource Exhaustion

<2.3.1-r0
  • L
CVE-2024-23184

<2.3.21.1-r0
  • M
CVE-2020-24386

<2.3.13-r0
  • H
Out-of-Bounds

<2.3.5.1-r0
  • H
Improper Input Validation

<2.3.13-r0
  • M
Use After Free

<2.3.10.1-r0
  • H
Out-of-bounds Read

<2.3.11.3-r0
  • H
NULL Pointer Dereference

<2.3.10.1-r0
  • M
Improper Input Validation

<2.3.10.1-r0
  • H
Missing Release of Resource after Effective Lifetime

<2.3.1-r0
  • H
Information Exposure

<2.3.1-r0