Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-27851

Опубликовано: 12 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

РелизСтатусПримечание
devel

not-affected

2.4.2+dfsg1-3ubuntu3
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

not-affected

code not present
noble

not-affected

code not present
questing

released

1:2.4.1+dfsg1-5ubuntu4.2
resolute

released

1:2.4.2+dfsg1-3ubuntu2.1

Показывать по

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
nvd
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
debian
3 месяца назад

When safe filter is used with variable expansion, all following pipeli ...

CVSS3: 7.4
github
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

suse-cvrf
около 2 месяцев назад

Security update for dovecot24

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3