<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:06:52.953546+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:6529</id>
    <title>ALSA-2024:6529 — Moderate: dovecot security update</title>
    <updated>2026-10-03T23:06:53.280720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: dovecot, AlmaLinux:9: dovecot-devel, AlmaLinux:9: dovecot-mysql, AlmaLinux:9: dovecot-pgsql, AlmaLinux:9: dovecot-pigeonhole</p>
<p>Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.</p>
<p>Security Fix(es):</p>
<p>* dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)
* dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:6529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06559</id>
    <title>bdu:2024-06559</title>
    <updated>2026-10-03T23:06:53.280799+00:00</updated>
    <content>bdu:2024-06559</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0710</id>
    <title>certfr-2024-avi-0710 — De multiples vulnérabilités ont été découvertes dans les produits Dovecot. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T23:06:53.280818+00:00</updated>
    <content>certfr-2024-avi-0710</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258879</id>
    <title>EUVD-2026-258879</title>
    <updated>2026-10-03T23:06:53.280834+00:00</updated>
    <content>EUVD-2026-258879</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23184</id>
    <title>fkie_cve-2024-23184</title>
    <updated>2026-10-03T23:06:53.280846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5f48-j349-fj3m</id>
    <title>GHSA-5f48-j349-fj3m</title>
    <updated>2026-10-03T23:06:53.280872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5f48-j349-fj3m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23184</id>
    <title>gsd-2024-23184</title>
    <updated>2026-10-03T23:06:53.280889+00:00</updated>
    <content>gsd-2024-23184</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2009</id>
    <title>OESA-2024-2009 — dovecot security update</title>
    <updated>2026-10-03T23:06:53.280901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: dovecot, openEuler:24.03-LTS: dovecot, openEuler:22.03-LTS-SP4: dovecot, openEuler:22.03-LTS-SP3: dovecot, openEuler:20.03-LTS-SP4: dovecot</p>
<p>Dovecot is an IMAP server for Linux/UNIX-like systemsa wrapper package that will just handle common things for all versioned dovecot packages.</p>
<p>Security Fix(es):</p>
<p>(CVE-2024-23184)</p>
<p>(CVE-2024-23185)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14274-1</id>
    <title>openSUSE-SU-2024:14274-1 — dovecot23-2.3.21.1-1.1 on GA media</title>
    <updated>2026-10-03T23:06:53.280931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dovecot23-2.3.21.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14274-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oxdc-adv-2024-0002</id>
    <title>OXDC-ADV-2024-0002 — OX Dovecot Pro Security Advisory OXDC-ADV-2024-0002</title>
    <updated>2026-10-03T23:06:53.280950+00:00</updated>
    <content>OXDC-ADV-2024-0002</content>
    <link href="https://cve.radiocsirt.org/vuln/oxdc-adv-2024-0002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6465</id>
    <title>RHSA-2024:6465 — Red Hat Security Advisory: dovecot security update</title>
    <updated>2026-10-03T23:06:53.280965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dovecot: using a large number of address headers may trigger a denial of service dovecot: very large headers can cause resource exhaustion when parsing message</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23184</id>
    <title>UBUNTU-CVE-2024-23184</title>
    <updated>2026-10-03T23:06:53.280984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dovecot, Ubuntu:24.04:LTS: dovecot</p>
<p>Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1867</id>
    <title>WID-SEC-W-2024-1867 — Dovecot: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T23:06:53.281006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Dovecot ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1867"/>
  </entry>
</feed>
