Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42393

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in dovecot. The comparison mechanism for doveadm passwords and API keys is not fully timing safe. A remote attacker, with network access to the doveadm service, could repeatedly make requests and accurately measure response timings. This could allow the attacker to learn the length of the configured secret, which reduces the effort needed to guess the secret value. The secret value itself is not directly disclosed by this vulnerability.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the doveadm service to only trusted clients. This can be achieved by configuring firewall rules to limit inbound connections to the doveadm service's port from known, secure IP addresses or subnets. Consult your system's firewall documentation (e.g., firewalld or iptables) for specific configuration steps.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2525568dovecot: Dovecot: Information disclosure via timing attack on `doveadm` password/API key comparison

EPSS

Процентиль: 4%
0.00145
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
nvd
15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
debian
15 дней назад

The comparison used for the doveadm password and API key is not fully ...

CVSS3: 3.1
github
15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
11 дней назад

Security update for dovecot24

EPSS

Процентиль: 4%
0.00145
Низкий

3.1 Low

CVSS3