Exim 4.100.1 Patches Four Flaws Including Proxy Protocol Heap Corruption and SMTP Smuggling
Exim released version 4.100.1 on September 18, 2026, fixing four vulnerabilities affecting versions 4.83 through 4.100 depending on configuration: an out-of-bounds write in Proxy Protocol v1 handling (GCVE-25-2026-09-50-1), an uninitialized memory data leak…
Exim maintainers released version 4.100.1 on September 18, 2026, to patch four security flaws in the widely used mail transfer agent, affecting versions 4.83 through 4.100 depending on configuration. The most critical is GCVE-25-2026-09-50-1, an out-of-bounds write in the Proxy Protocol v1 handler that allows a heap over-read of approximately 230 bytes and a NUL-byte write, which could lead to crashes and potential exploitation; this flaw requires Proxy Protocol to be enabled, limiting exposure for some deployments. GCVE-25-2026-09-55-1 leaks server stack data via uninitialized memory in Proxy Protocol v2 handling. GCVE-25-2026-09-51-1 is a low-severity GnuTLS use-after-free that can crash mail reception but requires the non-default tls_early_banner_hosts setting to be enabled. Finally, GCVE-25-2026-09-56-1 permits SMTP smuggling, allowing attackers to inject or submit email content that differs from what is logged by exploiting parsing inconsistencies between mail infrastructure components. The issues were reported by McCaulay Hudson of watchTowr. Administrators running affected versions with vulnerable configurations are strongly advised to upgrade to 4.100.1 and review upstream proxy configurations.
- Exim 4.100.1 was released on September 18, 2026, patching four vulnerabilities.
- Affected versions range from 4.83 to 4.100 depending on configuration.
- GCVE-25-2026-09-50-1: out-of-bounds write in Proxy Protocol v1 handling; allows ~230-byte heap over-read and NUL-byte write; requires Proxy Protocol to be enabled.
- GCVE-25-2026-09-55-1: leaks server stack data via uninitialized memory in Proxy Protocol v2 handling.
- GCVE-25-2026-09-51-1: low-severity GnuTLS use-after-free that can crash mail reception; requires the non-default tls_early_banner_hosts setting.
- GCVE-25-2026-09-56-1: SMTP smuggling that can alter or inject submitted email content differing from logged messages.
- The flaws were reported by McCaulay Hudson of watchTowr.
- Administrators are urged to upgrade to 4.100.1 and review upstream proxy configurations.
Coverage timelineoldest first · each row is one article
- · 6d agoExim Mail Server Hit by 4 Security Flaws Enabling SMTP Smuggling and Heap Corruption
GBHackers· 65
Exim Mail Server 4.100.1 patches critical out-of-bounds write and SMTP smuggling flaws that could allow remote code execution and message injection.
- · 6d agoExim Mail Server 4.100.1 Fixes 4 Security Flaws Including SMTP Smuggling and Heap Corruption
Cyber Security News· 55
Exim 4.100.1 patches four flaws, including high-severity Proxy Protocol heap corruption, uninitialized data leak, GnuTLS use-after-free, and SMTP smuggling.