Ad

CVE-2025-59028

MEDIUM CVSS 3.1: 5.3 EPSS 0.10%
Updated Mar 30, 2026
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-20 (Improper Input Validation)
Public PoC No

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments).

No publicly available exploits are known.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1