Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27851

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 7.4

Описание

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

A flaw was found in Dovecot. When the safe filter is used with variable expansion, subsequent pipelines on the same string are incorrectly interpreted as safe, allowing unsafe data to be unescaped. This can enable SQL (Structured Query Language) or LDAP (Lightweight Directory Access Protocol) injection attacks when used in authentication, potentially leading to unauthorized access or information disclosure.

Отчет

This issue is classified as Important severity primarily because: Exploitation requires a specific configuration where the safe filter is used in combination with variable expansion and subsequent pipelines on the same string during the authentication process. Successfully bypassing the safe filter allows unsafe data to be unescaped, enabling an attacker to execute SQL or LDAP injection attacks, which can lead directly to unauthorized access and significant information disclosure.

Меры по смягчению последствий

To mitigate this issue, avoid using the 'safe filter' feature in Dovecot configurations that involve variable expansion. Administrators should review Dovecot configuration files, typically found in /etc/dovecot/conf.d/, to identify and disable or modify any configurations that utilize the safe filter with variable expansion. A restart of the Dovecot service is necessary for these changes to take effect and may impact services relying on this feature.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotNot affected
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 8dovecotNot affected
Red Hat Enterprise Linux 9dovecotNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2476471dovecot: Dovecot: SQL/LDAP injection via incorrect safe filter interpretation with variable expansion

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
nvd
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
debian
3 месяца назад

When safe filter is used with variable expansion, all following pipeli ...

CVSS3: 7.4
github
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

suse-cvrf
около 2 месяцев назад

Security update for dovecot24

7.4 High

CVSS3