CVE-2020-28022: Exim

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs within MAIL FROM and RCPT TO commands.

Affected products

  • Exim Exim: from 4.00, before 4.94.2 (fixed in 4.94.2)

Published 2021-05-06. Last modified 2026-06-17.