CVE-2016-8652: Dovecot
Medium severity, CVSS 5.9. EPSS: 48.2% chance of exploitation in the next 30 days.
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
Affected products
- Dovecot Dovecot: up to and including 2.2.27
Published 2017-02-17. Last modified 2026-06-17.