CVE-2020-16094: Claws-Mail

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

Affected products

  • Claws-Mail Claws-Mail: up to and including 3.17.6
  • Fedoraproject Fedora: version 31 only; version 32 only; version 33 only

Published 2020-07-28. Last modified 2026-06-17.