Logo
vulnerabilityCVE-2026-33603
Name
CVE-2026-33603
Source
NVD ( link)Debian ( link)
Description
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dovecot
Exploitable

Vulnerability Ratings#


6.8
CVSSv31
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.3.21.1
Exploitable
openwrt
master
2.3.21-r1
Exploitable
openwrt
openwrt-25.12
2.3.21-r1
Exploitable
yocto
kirkstone
2.3.14
Exploitable
yocto
master
2.4.4
Not Affected
yocto
scarthgap
2.3.21.1
Exploitable