Description
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Published: 2026-09-19
Score: 7 High
EPSS: n/a
KEV: No
Impact: Out-of-bounds write that may allow memory corruption and remote code execution
Action: Apply Patch
AI Analysis

Impact

Exim before 4.100.1 contains an out-of-bounds write when the Proxy-Protocol is used with an attacker-controlled proxy, potentially leading to memory corruption. The weakness is an instance of CWE-787, where improper bounds checking allows a malicious input to overwrite adjacent memory. This can compromise confidentiality, integrity, and availability if exploited.

Affected Systems

All Exim installations running version 4.100.0 or earlier are affected. The vulnerability applies to the Exim email server product as listed by the CNA.

Risk and Exploitability

The vulnerability carries a CVSS score of 7, indicating moderate to high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation is known. The likely attack requires an attacker to control a proxy that forwards Proxy-Protocol packets to the vulnerable Exim instance; successful exploitation could result in memory corruption and potentially remote code execution. No official workaround is provided in the advisory.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Exim to version 4.100.1 or later to apply the vendor-published fix.
  • If Proxy-Protocol support is not required, disable or remove it to prevent exploitation until a patch is applied.
  • Add network-level restrictions to block connections from untrusted or attacker-controlled proxies that may send Proxy-Protocol headers.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Proxy-Protocol in Exim

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
First Time appeared Exim
Exim exim
Weaknesses CWE-787
CPEs cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
Vendors & Products Exim
Exim exim
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-19T22:46:24.545Z

Reserved: 2026-09-19T22:46:24.165Z

Link: CVE-2026-94054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-19T23:17:10.827

Modified: 2026-09-19T23:17:10.827

Link: CVE-2026-94054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses