CVE-2025-30189: Dovecot IMAP Server: Using auth caching causes the first lookup to be cached for all lookups
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30189?
CVE-2025-30189 is considered a high severity vulnerability due to the potential for user data mishandling.
How do I fix CVE-2025-30189?
To fix CVE-2025-30189, either install the fixed version of Dovecot IMAP Server or disable caching globally or for individual users.
What is the impact of CVE-2025-30189 on Dovecot IMAP Server?
The impact of CVE-2025-30189 includes incorrect user authentication due to cached information being shared among users.
Who is affected by CVE-2025-30189?
Any user of Dovecot IMAP Server with caching enabled is potentially affected by CVE-2025-30189.
When was CVE-2025-30189 disclosed?
CVE-2025-30189 was disclosed in October 2025.