Sploitus

CVE-2025-59032

1 known exploit for CVE-2025-59032

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

Dovecot
< 2.4.3
Open-xchange Dovecot
< 3.1.3
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.7% (51th percentile)
Weakness
CWE-229, CWE-20
NVD status
Modified
Published
2026-03-27
CVE-2025-59032 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-59032

Proof-of-concept code and exploit modules indexed by Sploitus