CVE-2020-28017: Exim

Critical severity, CVSS 9.8. EPSS: 36.9% chance of exploitation in the next 30 days.

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.

Affected products

  • Exim Exim: before 4.94.1 (fixed in 4.94.1)

Published 2021-05-06. Last modified 2026-06-17.