Exim Vulnerabilities and Affected Products
Vulnerabilities associated with Exim.
Products
Clear product- Exim24 vulnerabilities
- Exim Internet Mailer1 vulnerability
- libspf21 vulnerability
- Mail Transfer Agent (MTA)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66141HIGH | Generated title:Exim .forward File Privilege Escalation via Pipe Transport force_commandExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. CWE-829Jul 24, 2026 | CVSS7.4v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66140HIGH | Generated title:Exim Directory Traversal via Queue Name ArgumentsExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled. CWE-24Jul 24, 2026 | CVSS8.4v3.1 | EPSS0.272% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-48840MEDIUM | Generated title:Exim Proxy Configuration Uninitialized Stack Memory DisclosureExim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. CWE-839May 30, 2026 | CVSS5.3v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45185CRITICAL | Generated title:Exim BDAT Body Parsing Use-After-Free in GnuTLS ConfigurationsExim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code. CWE-416May 12, 2026 | CVSS9.8v3.1 | EPSS1.23% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40684MEDIUM | Generated title:Exim DNS PTR Record Handling Denial of Service VulnerabilityIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing. CWE-684Apr 30, 2026 | CVSS5.9v3.1 | EPSS0.362% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40687MEDIUM | Generated title:Exim SPA Authentication Driver Out-of-bounds Write and Information DisclosureIn Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory. CWE-909Apr 30, 2026 | CVSS4.8v3.1 | EPSS0.373% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Exim Out-of-Bounds Read in UTF-8 OperatorsIn Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message. CWE-125Apr 30, 2026 | CVSS3.7v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-40685MEDIUM | Generated title:Exim Out-of-Bounds Heap Write in JSON LookupIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping. | CVSS6.5v3.1 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67896HIGH | Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation. CWE-122Dec 14, 2025 | CVSS7.0v3.1 | EPSS0.463% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30232HIGH | A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. CWE-416Mar 27, 2025 | CVSS8.1v3.1 | EPSS0.521% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26794HIGH | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.) CWE-89Feb 21, 2025 | CVSS7.5v3.1 | EPSS77.2% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-39929MEDIUM | Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users. CWE-116Jul 4, 2024 | CVSS5.4v3.1 | EPSS41.2% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Exim dnsdb Out-Of-Bounds Read Information Disclosure VulnerabilityExim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can … CWE-125May 3, 2024 | CVSS3.1v3.0 | EPSS1.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-42117CRITICAL | Exim Improper Neutralization of Special Elements Remote Code Execution VulnerabilityExim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this… CWE-138May 3, 2024 | CVSS9.8v3.1 | EPSS5.72% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42116CRITICAL | Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution VulnerabilityExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage thi… CWE-121May 3, 2024 | CVSS9.8v3.1 | EPSS3.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42115CRITICAL | Exim AUTH Out-Of-Bounds Write Remote Code Execution VulnerabilityExim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability … CWE-787May 3, 2024 | CVSS9.8v3.0 | EPSS9.96% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42114MEDIUM | Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure VulnerabilityExim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage th… CWE-125May 3, 2024 | CVSS5.3v3.1 | EPSS28.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-16928CRITICAL | Exim Out-of-bounds Write VulnerabilityExim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command. | CVSS9.8v3.1 | EPSS41.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-15846CRITICAL | Exim before 4.92.2 Trailing Backslash Remote Code ExecutionExim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. Sep 6, 2019 | CVSS9.8v3.0 | EPSS35.7% | PoCs1 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2019-10149CRITICAL | Exim Mail Transfer Agent (MTA) Improper Input ValidationA flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | CVSS9.8v3.1 | EPSS>99.9% | PoCs22 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-6789CRITICAL | Exim Buffer Overflow VulnerabilityAn issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely. | CVSS9.8v3.1 | EPSS81.7% | PoCs6 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Exim Exim Improper Restriction of Operations within the Bounds of a Memory BufferHeap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server. CWE-119Oct 31, 2012 | CVSS6.8v2.0 | EPSS8.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2010-4345HIGH | Exim Privilege Escalation VulnerabilityExim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive. | CVSS7.8v3.1 | EPSS18.1% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2010-4344CRITICAL | Exim Heap-Based Buffer Overflow VulnerabilityHeap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging. | CVSS9.8v3.1 | EPSS71.9% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |