Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27851

Опубликовано: 12 мая 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 9.1
EPSS Низкий

Описание

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 2.4.4 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия до 3.1.5 (исключая)

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-235
CWE-89

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
redhat
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
debian
3 месяца назад

When safe filter is used with variable expansion, all following pipeli ...

CVSS3: 7.4
github
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

suse-cvrf
около 2 месяцев назад

Security update for dovecot24

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-235
CWE-89