CVE-2020-16094: Claws-Mail
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
Affected products
- Claws-Mail Claws-Mail: up to and including 3.17.6
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
Published 2020-07-28. Last modified 2026-06-17.