CVE-2019-10691: Dovecot

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

Affected products

  • Dovecot Dovecot: before 2.3.5.2 (fixed in 2.3.5.2)
  • Opensuse Leap: version 15.0 only

Published 2019-04-24. Last modified 2026-06-17.