<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Mail-Server on kalfaoglu.net</title><link>https://blog.kalfaoglu.net/tags/mail-server/</link><description>Recent content in Mail-Server on kalfaoglu.net</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 29 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.kalfaoglu.net/tags/mail-server/index.xml" rel="self" type="application/rss+xml"/><item><title>Dovecot 2.4.4 Patches Five Vulnerabilities — Update Now</title><link>https://blog.kalfaoglu.net/posts/2026-05-29-dovecot-oxdc-2026-0002-en/</link><pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate><guid>https://blog.kalfaoglu.net/posts/2026-05-29-dovecot-oxdc-2026-0002-en/</guid><description>&lt;p&gt;On 5 May 2026, the Dovecot team published security advisory &lt;a href="https://seclists.org/fulldisclosure/2026/May/2"&gt;OXDC-2026-0002&lt;/a&gt;, covering five vulnerabilities fixed in &lt;strong&gt;OX Dovecot CE 2.4.4&lt;/strong&gt; (and Pro 3.1.5). If you are running Dovecot CE 2.4.3 or earlier, this is your prompt to upgrade.&lt;/p&gt;
&lt;h2 id="whats-in-the-advisory"&gt;What&amp;rsquo;s in the advisory&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-27851 — SQL/LDAP injection via variable expansion (CVSS 7.4)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The most serious of the five. When the &lt;code&gt;safe&lt;/code&gt; filter is used in Dovecot&amp;rsquo;s variable expansion (&lt;code&gt;lib-var-expand&lt;/code&gt;), it incorrectly treats all subsequent pipelines on the same string as safe too. The result: attacker-controlled data can bypass escaping and land unmodified in SQL or LDAP queries used for authentication. No public exploit exists yet, but CVSS 7.4 with a network attack vector and no required privileges is not something to sit on. If you cannot upgrade immediately, the workaround is to avoid the &lt;code&gt;safe&lt;/code&gt; filter in your configuration until you can.&lt;/p&gt;</description></item></channel></rss>