Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-42393

15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-42393

15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-42393

15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2026-42393

15 дней назад

The comparison used for the doveadm password and API key is not fully ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-j4gv-hpmc-xf3m

15 дней назад

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3919-1

10 дней назад

Security update for dovecot22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21720-1

11 дней назад

Security update for dovecot24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42393

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
0%
Низкий
15 дней назад
redhat логотип
CVE-2026-42393

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
0%
Низкий
15 дней назад
nvd логотип
CVE-2026-42393

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
0%
Низкий
15 дней назад
debian логотип
CVE-2026-42393

The comparison used for the doveadm password and API key is not fully ...

CVSS3: 3.1
0%
Низкий
15 дней назад
github логотип
GHSA-j4gv-hpmc-xf3m

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
0%
Низкий
15 дней назад
suse-cvrf логотип
SUSE-SU-2026:3919-1

Security update for dovecot22

10 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21720-1

Security update for dovecot24

11 дней назад

Уязвимостей на страницу