CVE-2018-20954: Mailpile
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.
Affected products
- Mailpile Mailpile: version 0.5.0 only; version 0.5.1 only; version 0.5.2 only; version 1.0.0 only
Published 2019-08-08. Last modified 2026-06-17.