๐Ÿ” CVE Alert

CVE-2020-37248

MEDIUM 6.5
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

CWE CWE-348
Vendor offlineimap
Product offlineimap
Published Jun 8, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for offlineimap offlineimap

Be the first to know when new medium vulnerabilities affecting offlineimap offlineimap are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

OfflineIMAP / OfflineIMAP
0 < 8.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74 github.com: https://github.com/OfflineIMAP/offlineimap3/issues/222 github.com: https://github.com/OfflineIMAP/offlineimap/issues/669 pypi.org: https://pypi.org/project/offlineimap/#history openwall.com: http://www.openwall.com/lists/oss-security/2026/06/08/3