{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2025/cve-2025-59031-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T15:52:10Z",
      "generator": {
        "date": "2026-07-28T15:52:10Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-59031-ELS_OS-RHEL7ELS",
      "initial_release_date": "2025-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2025-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T15:52:10Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-59031"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-devel@2.2.36-8.el7?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-devel@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-mysql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-pigeonhole@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/dovecot-pgsql@2.2.36-8.el7?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot@2.2.36-8.el7.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-devel@2.2.36-8.el7.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-devel@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-mysql@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-pigeonhole@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_id": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dovecot-pgsql@2.2.36-8.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-devel-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-devel-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-mysql-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-mysql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pigeonhole-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dovecot-pgsql-1:2.2.36-8.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64"
        },
        "product_reference": "dovecot-pgsql-1:2.2.36-8.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-59031",
      "cwe": {
        "id": "CWE-611",
        "name": "Improper Restriction of XML External Entity Reference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
          "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-59031"
        }
      ],
      "release_date": "2026-03-27T09:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T12:01:15.948483Z",
          "details": "This issue only affects deployments that explicitly enable Dovecot’s optional decode2text.sh attachment-to-text helper for FTS; it is not used by default and has been removed or disabled in recent vendor releases. Exploitation requires at least low, authenticated privileges (PR:L) to trigger indexing and results only in a limited confidentiality exposure via FTS index content, with no integrity or availability impact and no code execution. Given the preconditioned, non-default configuration and absence of known public exploits, this is a low-priority item for typical centrally managed server/VM environments.",
          "product_ids": [
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.i686",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-devel-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-mysql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pgsql-1:2.2.36-8.el7.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:dovecot-pigeonhole-1:2.2.36-8.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}