[Git][security-tracker-team/security-tracker][master] Track fixed version for dovecot issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 05:37:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
56a02fa9 by Salvatore Bonaccorso at 2026-09-01T06:36:46+02:00
Track fixed version for dovecot issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1651,10 +1651,10 @@ CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard libr
 CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
 	NOT-FOR-US: SOY
 CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73209-imap-login-crash-self-recursion-on-zero-output-decompress-chunks
 CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73208-auth-db-oauth2-aud-claim-used-as-fallback-for-missing-scope-claim
 CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin  ...)
 	NOT-FOR-US: WordPress plugin
@@ -1683,10 +1683,10 @@ CVE-2026-56854 (The source-address critical option in the Permissions returned b
 	NOTE: https://github.com/golang/go/issues/80213
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/e557b08ec2b4f5dd00f38356919fc7b051dd88f8 (v0.55.0)
 CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52687-imap-compress-zstd-can-cause-excessive-memory-usage
 CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
 CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of  ...)
 	NOT-FOR-US: Osbil Technology oPanel
@@ -1695,51 +1695,51 @@ CVE-2026-4378 (Improper neutralization of input during web page generation ('cro
 CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42395-single-nul-byte-xclient-forward-payload-crashes
 CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully  ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42393-doveadm-password-or-api-key-length-can-still-be-leaked-with-timing-comparisons
 CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
 CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
 CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy  ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
 CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce
 CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
 	NOT-FOR-US: Synology
 CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40205-oauth2-passdb-scope-enforcement-bypass-via-or-semantics-in-remote-validation-path
 CVE-2026-40204 (None None None No publicly available exploits are known.)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
 CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
 CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40019-v2-4-3-regression-managesieve-login-pre-auth-infinite-loop
 CVE-2026-40018 (None None None No publicly available exploits are known.)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40018-mysql-multi-byte-escaping-wrong
 CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40017-imap-thread-o-m3-cpu-dos-via-crc32-hash-collision-in-strmap-mail-index-strmap-c-hash2-c
 CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
 CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c
 CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40013-pigeonhole-stack-buffer-underflow-in-pigeonhole-managesieve-checkscript-putscript
 CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
 	NOT-FOR-US: WordPress plugin
@@ -1764,22 +1764,22 @@ CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control.
 	[trixie] - golang-github-grpc-ecosystem-grpc-gateway <no-dsa> (Minor issue)
 	NOTE: https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc (v2.29.0)
 CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33607-dovecot-imap-list-match-sub-exponential-backtracking-%E2%80%94-cpu-denial-of-service
 CVE-2026-33606 (Mail content stored by a user can be crafted so that it is interpreted ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33606-dsync-mail-content-can-cause-dsync-protocol-injection
 CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
 CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33604-smtp-smuggling-via-missing-dot-stuffing-after-bare-carriage-return
 CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor
 CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
-	- dovecot <unfixed> (bug #1146018)
+	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-27852-dos-by-sending-mail-with-bad-header
 CVE-2026-19423 (The Ultimate Member  WordPress plugin before 2.13.0 does not validate  ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a02fa9c9b7ed1ff17c3d3cfa3461f914d367e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a02fa9c9b7ed1ff17c3d3cfa3461f914d367e9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/02ffbe01/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list