CVE-2016-8652: Dovecot

Medium severity, CVSS 5.9. EPSS: 48.2% chance of exploitation in the next 30 days.

The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.

Affected products

  • Dovecot Dovecot: up to and including 2.2.27

Published 2017-02-17. Last modified 2026-06-17.