Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27851

Опубликовано: 12 мая 2026
Источник: debian
EPSS Низкий

Описание

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.4.4+dfsg1-1package
dovecotfixed1:2.4.1+dfsg1-6+deb13u6trixiepackage
dovecotnot-affectedbookwormpackage
dovecotnot-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/12/6

  • Fixed by: https://github.com/dovecot/core/commit/d75c04e8ccbeb70d66d05938665fe145175ac1b5 (2.4.4)

EPSS

Процентиль: 34%
0.00406
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
redhat
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
nvd
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
github
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

suse-cvrf
около 2 месяцев назад

Security update for dovecot24

EPSS

Процентиль: 34%
0.00406
Низкий