CVE-2020-28200: Dovecot

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

Affected products

  • Dovecot Dovecot: before 2.3.15 (fixed in 2.3.15)
  • Fedoraproject Fedora: version 33 only; version 34 only

Published 2021-06-28. Last modified 2026-06-17.