AI analysis
CVE-2026-94054 is an out-of-bounds write (CWE-787) in the Exim mail transfer agent's parsing of the Proxy Protocol header, fixed in Exim 4.100.1. It is triggered when Exim is configured to accept Proxy Protocol (a feature used to preserve real client IPs when Exim sits behind a load balancer or proxy) and the host supplying the PROXY header is attacker-controlled, allowing a crafted header line to write past the bounds of a buffer in the network-facing SMTP service. An attacker who meets that precondition gains memory corruption on a remotely reachable process; the CVSS 3.1 score of 7.0 (AV:N/AC:H/PR:N/UI:N) reflects high integrity impact with limited confidentiality and availability impact, consistent with a buffer overflow that could compromise the Exim daemon. Only deployments running a release before 4.100.1 with Proxy Protocol enabled and an insufficiently restricted trust list are affected; Exim servers without the proxy_protocol feature in use are not. No exploitation in the wild has been reported, there is no CISA KEV entry, and no public proof-of-concept is known.
What to do: Upgrade to Exim 4.100.1 or later. Until you can upgrade, restrict the proxy_protocol host list in your Exim configuration so only trusted load balancers may send PROXY headers, or disable Proxy Protocol on any listener reachable by untrusted hosts. Audit your Exim config (proxy_protocol setting) and firewall rules to confirm no internet-reachable path can deliver a Proxy Protocol header directly to Exim.
Affected
| Exim (University of Cambridge) Exim Internet Mailer (mail transfer agent) | All releases before 4.100.1 when Proxy Protocol is in use with an attacker-controlled proxy (i.e., the proxy_protocol feature is enabled and the header source i |
Estimated exposure
large≈10,000–100,000 internet-facing Exim servers with Proxy Protocol enabled — Exim is one of the most common SMTP server banners seen in public internet-wide scans (on the order of a million Exim instances), but only the minority subset that enables Proxy Protocol — typically clustered/containerized mail setups…
Description
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.