Use-After-Free Vulnerability in Exim Email Server by Exim
CVE-2026-94055

3.7LOW

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-94055?

A specific use-after-free vulnerability exists in Exim versions prior to 4.100.1, triggered when using certain non-default TLS configurations with GnuTLS. This flaw can lead to unexpected behavior or potential system compromises, making it crucial for users to review their configurations and upgrade to secure versions to mitigate risks.

Affected Version(s)

Exim 4.98 < 4.100.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.