CVE-2019-20790: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Affected products
- Fedoraproject Fedora: version 33 only; version 34 only
- Pypolicyd-Spf Project Pypolicyd-Spf: version 2.0.2 only
- Trusteddomain Opendmarc: from 1.3.0, up to and including 1.3.2; version 1.4.0 only
Published 2020-04-27. Last modified 2026-06-17.