Stack Memory Exposure in Exim Mail Transfer Agent from Attacker-Controlled Proxies
CVE-2026-94056

7.5HIGH

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-94056?

A vulnerability in Exim versions before 4.100.1 allows attackers to exploit the Proxy-Protocol feature, enabling them to read uninitialized data from the stack memory. This can potentially expose sensitive information and compromise the security of systems utilizing affected versions of Exim. It is crucial for administrators to update to the patched version to mitigate this risk.

Affected Version(s)

Exim 4.83 < 4.100.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.