Vulnerabilities
63 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66140 +1 in the same advisory: …66141 | Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-na Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-48840 | Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-45185 | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2026-40685 | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-67896 | Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-30232 | A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-26794 | Critical Unauthenticated SQL Injection in Exim 4.98 Exim, the widely deployed open-source mail transfer agent, is vulnerable to remote SQL injection (CVE-2025-26794, CWE-89) in version 4.98 before 4.98.1. The flaw is reachable over the network when a server uses SQLite for its hints database together with ETRN serialization, and per the CVSS vector requires no privileges or user interaction, with high impact on confidentiality, integrity, and availability. A successful attacker could manipulate the SQLite-backed data Exim relies on and disrupt mail handling, consistent with the critical 9.8 score. Only sites running Exim 4.98.x on affected configurations are exposed; sites with certain non-default rate-limit configurations need version 4.99.1 for the SQL injection to be fully resolved. No public proof-of-concept or CISA KEV entry exists yet, but EPSS assigns a 77.2% probability of exploitation within 30 days (100th percentile), so patching should be treated as urgent. Do: Upgrade Exim to 4.98.1 or later; sites using certain non-default rate-limit configurations should move to 4.99.1, since the SQL injection is only fully resolved there. Administrators should check whether their configuration uses SQLite for the hints database and ETRN serialization, and until patching can mitigate by disabling SQLite hints/ETRN serialization or restricting network access to the SMTP service. Given the 77.2% EPSS score, treat this as a priority patch even though exploitation has not yet been confirmed. | 9.8 | 77% |
| largelikely on the order of tens of thousands of mail servers (a configured subset of Exim's 1M+ installed base) | ||
| CVE-2024-39929 | Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanis Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users. NVD description · AI analysis pending | 5.4 | 41% | PoC |
| — | |
| CVE-2023-42115 | Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434. NVD description · AI analysis pending | 9.8 group max | 10% |
| — | ||
| CVE-2023-51766 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports . but some other popular e-mail servers do not. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2022-4523 | A vulnerability, which was classified as problematic, has been found in vexim2. A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-3620 | A vulnerability was found in Exim and classified as problematic. A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-3559 | A vulnerability was found in Exim and classified as problematic. A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability. NVD description · AI analysis pending | 7.5 | 4% |
| — | ||
| CVE-2022-37452 | Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2022-37451 | Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. NVD description · AI analysis pending | 7.5 | 3% | PoC |
| — | |
| CVE-2021-38371 | The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2020-28018 | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. NVD description · AI analysis pending | 9.8 group max | 57% |
| — | ||
| CVE-2020-12783 | Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c. Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c. NVD description · AI analysis pending | 7.5 | 5% | PoC |
| — | |
| CVE-2020-8015 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2019-19920 | sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805. NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2019-18820 +1 in the same advisory: …18821 | Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — |