{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27851.json"
      }
    ],
    "title": "dovecot: Dovecot: SQL/LDAP injection via incorrect safe filter interpretation with variable expansion",
    "tracking": {
      "current_release_date": "2026-07-09T16:30:27+00:00",
      "generator": {
        "date": "2026-07-09T16:30:27+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.2"
        }
      },
      "id": "CVE-2026-27851",
      "initial_release_date": "2026-05-12T13:28:43.846000+00:00",
      "revision_history": [
        {
          "date": "2026-05-12T13:28:43.846000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-29T19:20:31+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-09T16:30:27+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 10",
                "product": {
                  "name": "Red Hat Enterprise Linux 10",
                  "product_id": "red_hat_enterprise_linux_10",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:10"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 10"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 6",
                "product": {
                  "name": "Red Hat Enterprise Linux 6",
                  "product_id": "red_hat_enterprise_linux_6",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:6"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 6"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 8",
                "product": {
                  "name": "Red Hat Enterprise Linux 8",
                  "product_id": "red_hat_enterprise_linux_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 9",
                "product": {
                  "name": "Red Hat Enterprise Linux 9",
                  "product_id": "red_hat_enterprise_linux_9",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 9"
          },
          {
            "category": "product_version",
            "name": "dovecot.src",
            "product": {
              "name": "dovecot.src",
              "product_id": "dovecot.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "dovecot-mysql",
            "product": {
              "name": "dovecot-mysql",
              "product_id": "dovecot-mysql",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot-mysql"
              }
            }
          },
          {
            "category": "product_version",
            "name": "dovecot-devel",
            "product": {
              "name": "dovecot-devel",
              "product_id": "dovecot-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "dovecot",
            "product": {
              "name": "dovecot",
              "product_id": "dovecot",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot"
              }
            }
          },
          {
            "category": "product_version",
            "name": "dovecot-pgsql",
            "product": {
              "name": "dovecot-pgsql",
              "product_id": "dovecot-pgsql",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot-pgsql"
              }
            }
          },
          {
            "category": "product_version",
            "name": "dovecot-pigeonhole",
            "product": {
              "name": "dovecot-pigeonhole",
              "product_id": "dovecot-pigeonhole",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/dovecot-pigeonhole"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot"
        },
        "product_reference": "dovecot",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot-devel"
        },
        "product_reference": "dovecot-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot-mysql"
        },
        "product_reference": "dovecot-mysql",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot-pgsql"
        },
        "product_reference": "dovecot-pgsql",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot-pigeonhole"
        },
        "product_reference": "dovecot-pigeonhole",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot.src as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:dovecot.src"
        },
        "product_reference": "dovecot.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot"
        },
        "product_reference": "dovecot",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot-devel"
        },
        "product_reference": "dovecot-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot-mysql"
        },
        "product_reference": "dovecot-mysql",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot-pgsql"
        },
        "product_reference": "dovecot-pgsql",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot-pigeonhole"
        },
        "product_reference": "dovecot-pigeonhole",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot.src as a component of Red Hat Enterprise Linux 6",
          "product_id": "red_hat_enterprise_linux_6:dovecot.src"
        },
        "product_reference": "dovecot.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot"
        },
        "product_reference": "dovecot",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot-devel"
        },
        "product_reference": "dovecot-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot-mysql"
        },
        "product_reference": "dovecot-mysql",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot-pgsql"
        },
        "product_reference": "dovecot-pgsql",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot-pigeonhole"
        },
        "product_reference": "dovecot-pigeonhole",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:dovecot.src"
        },
        "product_reference": "dovecot.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot"
        },
        "product_reference": "dovecot",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot-devel"
        },
        "product_reference": "dovecot-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot-mysql"
        },
        "product_reference": "dovecot-mysql",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot-pgsql"
        },
        "product_reference": "dovecot-pgsql",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot-pigeonhole"
        },
        "product_reference": "dovecot-pigeonhole",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:dovecot.src"
        },
        "product_reference": "dovecot.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-27851",
      "cwe": {
        "id": "CWE-89",
        "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
      },
      "discovery_date": "2026-05-12T14:01:35.826747+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_enterprise_linux_10:dovecot",
            "red_hat_enterprise_linux_10:dovecot-devel",
            "red_hat_enterprise_linux_10:dovecot-mysql",
            "red_hat_enterprise_linux_10:dovecot-pgsql",
            "red_hat_enterprise_linux_10:dovecot-pigeonhole",
            "red_hat_enterprise_linux_10:dovecot.src",
            "red_hat_enterprise_linux_8:dovecot",
            "red_hat_enterprise_linux_8:dovecot-devel",
            "red_hat_enterprise_linux_8:dovecot-mysql",
            "red_hat_enterprise_linux_8:dovecot-pgsql",
            "red_hat_enterprise_linux_8:dovecot-pigeonhole",
            "red_hat_enterprise_linux_8:dovecot.src",
            "red_hat_enterprise_linux_9:dovecot",
            "red_hat_enterprise_linux_9:dovecot-devel",
            "red_hat_enterprise_linux_9:dovecot-mysql",
            "red_hat_enterprise_linux_9:dovecot-pgsql",
            "red_hat_enterprise_linux_9:dovecot-pigeonhole",
            "red_hat_enterprise_linux_9:dovecot.src"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2476471"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Dovecot. When the safe filter is used with variable expansion, subsequent pipelines on the same string are incorrectly interpreted as safe, allowing unsafe data to be unescaped. This can enable SQL (Structured Query Language) or LDAP (Lightweight Directory Access Protocol) injection attacks when used in authentication, potentially leading to unauthorized access or information disclosure.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "dovecot: Dovecot: SQL/LDAP injection via incorrect safe filter interpretation with variable expansion",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This issue is classified as Important severity primarily because:\n\nExploitation requires a specific configuration where the safe filter is used in combination with variable expansion and subsequent pipelines on the same string during the authentication process.\n\nSuccessfully bypassing the safe filter allows unsafe data to be unescaped, enabling an attacker to execute SQL or LDAP injection attacks, which can lead directly to unauthorized access and significant information disclosure.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_enterprise_linux_6:dovecot",
          "red_hat_enterprise_linux_6:dovecot-devel",
          "red_hat_enterprise_linux_6:dovecot-mysql",
          "red_hat_enterprise_linux_6:dovecot-pgsql",
          "red_hat_enterprise_linux_6:dovecot-pigeonhole",
          "red_hat_enterprise_linux_6:dovecot.src"
        ],
        "known_not_affected": [
          "red_hat_enterprise_linux_10:dovecot",
          "red_hat_enterprise_linux_10:dovecot-devel",
          "red_hat_enterprise_linux_10:dovecot-mysql",
          "red_hat_enterprise_linux_10:dovecot-pgsql",
          "red_hat_enterprise_linux_10:dovecot-pigeonhole",
          "red_hat_enterprise_linux_10:dovecot.src",
          "red_hat_enterprise_linux_8:dovecot",
          "red_hat_enterprise_linux_8:dovecot-devel",
          "red_hat_enterprise_linux_8:dovecot-mysql",
          "red_hat_enterprise_linux_8:dovecot-pgsql",
          "red_hat_enterprise_linux_8:dovecot-pigeonhole",
          "red_hat_enterprise_linux_8:dovecot.src",
          "red_hat_enterprise_linux_9:dovecot",
          "red_hat_enterprise_linux_9:dovecot-devel",
          "red_hat_enterprise_linux_9:dovecot-mysql",
          "red_hat_enterprise_linux_9:dovecot-pgsql",
          "red_hat_enterprise_linux_9:dovecot-pigeonhole",
          "red_hat_enterprise_linux_9:dovecot.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-27851"
        },
        {
          "category": "external",
          "summary": "RHBZ#2476471",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476471"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-27851",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27851"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-27851",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27851"
        },
        {
          "category": "external",
          "summary": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json",
          "url": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json"
        }
      ],
      "release_date": "2026-05-12T13:28:43.846000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "To mitigate this issue, avoid using the 'safe filter' feature in Dovecot configurations that involve variable expansion.\n\nAdministrators should review Dovecot configuration files, typically found in `/etc/dovecot/conf.d/`, to identify and disable or modify any configurations that utilize the `safe filter` with variable expansion. \nA restart of the Dovecot service is necessary for these changes to take effect and may impact services relying on this feature.",
          "product_ids": [
            "red_hat_enterprise_linux_6:dovecot",
            "red_hat_enterprise_linux_6:dovecot-devel",
            "red_hat_enterprise_linux_6:dovecot-mysql",
            "red_hat_enterprise_linux_6:dovecot-pgsql",
            "red_hat_enterprise_linux_6:dovecot-pigeonhole",
            "red_hat_enterprise_linux_6:dovecot.src"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "red_hat_enterprise_linux_6:dovecot",
            "red_hat_enterprise_linux_6:dovecot-devel",
            "red_hat_enterprise_linux_6:dovecot-mysql",
            "red_hat_enterprise_linux_6:dovecot-pgsql",
            "red_hat_enterprise_linux_6:dovecot-pigeonhole",
            "red_hat_enterprise_linux_6:dovecot.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_enterprise_linux_10:dovecot",
            "red_hat_enterprise_linux_10:dovecot-devel",
            "red_hat_enterprise_linux_10:dovecot-mysql",
            "red_hat_enterprise_linux_10:dovecot-pgsql",
            "red_hat_enterprise_linux_10:dovecot-pigeonhole",
            "red_hat_enterprise_linux_10:dovecot.src",
            "red_hat_enterprise_linux_6:dovecot",
            "red_hat_enterprise_linux_6:dovecot-devel",
            "red_hat_enterprise_linux_6:dovecot-mysql",
            "red_hat_enterprise_linux_6:dovecot-pgsql",
            "red_hat_enterprise_linux_6:dovecot-pigeonhole",
            "red_hat_enterprise_linux_6:dovecot.src",
            "red_hat_enterprise_linux_8:dovecot",
            "red_hat_enterprise_linux_8:dovecot-devel",
            "red_hat_enterprise_linux_8:dovecot-mysql",
            "red_hat_enterprise_linux_8:dovecot-pgsql",
            "red_hat_enterprise_linux_8:dovecot-pigeonhole",
            "red_hat_enterprise_linux_8:dovecot.src",
            "red_hat_enterprise_linux_9:dovecot",
            "red_hat_enterprise_linux_9:dovecot-devel",
            "red_hat_enterprise_linux_9:dovecot-mysql",
            "red_hat_enterprise_linux_9:dovecot-pgsql",
            "red_hat_enterprise_linux_9:dovecot-pigeonhole",
            "red_hat_enterprise_linux_9:dovecot.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_enterprise_linux_10:dovecot",
            "red_hat_enterprise_linux_10:dovecot-devel",
            "red_hat_enterprise_linux_10:dovecot-mysql",
            "red_hat_enterprise_linux_10:dovecot-pgsql",
            "red_hat_enterprise_linux_10:dovecot-pigeonhole",
            "red_hat_enterprise_linux_10:dovecot.src",
            "red_hat_enterprise_linux_6:dovecot",
            "red_hat_enterprise_linux_6:dovecot-devel",
            "red_hat_enterprise_linux_6:dovecot-mysql",
            "red_hat_enterprise_linux_6:dovecot-pgsql",
            "red_hat_enterprise_linux_6:dovecot-pigeonhole",
            "red_hat_enterprise_linux_6:dovecot.src",
            "red_hat_enterprise_linux_8:dovecot",
            "red_hat_enterprise_linux_8:dovecot-devel",
            "red_hat_enterprise_linux_8:dovecot-mysql",
            "red_hat_enterprise_linux_8:dovecot-pgsql",
            "red_hat_enterprise_linux_8:dovecot-pigeonhole",
            "red_hat_enterprise_linux_8:dovecot.src",
            "red_hat_enterprise_linux_9:dovecot",
            "red_hat_enterprise_linux_9:dovecot-devel",
            "red_hat_enterprise_linux_9:dovecot-mysql",
            "red_hat_enterprise_linux_9:dovecot-pgsql",
            "red_hat_enterprise_linux_9:dovecot-pigeonhole",
            "red_hat_enterprise_linux_9:dovecot.src"
          ]
        }
      ],
      "title": "dovecot: Dovecot: SQL/LDAP injection via incorrect safe filter interpretation with variable expansion"
    }
  ]
}