CVE-2025-59028
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-03-27 09:16:18
Güncelleme
2026-03-30 13:26:29
Source Identifier
security@open-xchange.com
KEV Date Added
-