Description
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Published: 2026-09-19
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds write that may allow memory corruption and remote code execution
Action: Apply Patch
AI Analysis

Impact

Exim before 4.100.1 contains an out-of-bounds write when the Proxy-Protocol is used with an attacker-controlled proxy, potentially leading to memory corruption. The weakness is an instance of CWE-787, where improper bounds checking allows a malicious input to overwrite adjacent memory. This can compromise confidentiality, integrity, and availability if exploited.

Affected Systems

All Exim installations running version 4.100.0 or earlier are affected. The vulnerability applies to the Exim email server product as listed by the CNA.

Risk and Exploitability

The vulnerability carries a CVSS score of 7, indicating moderate to high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation is known. The likely attack requires an attacker to control a proxy that forwards Proxy-Protocol packets to the vulnerable Exim instance; successful exploitation could result in memory corruption and potentially remote code execution. No official workaround is provided in the advisory.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Exim to version 4.100.1 or later to apply the vendor-published fix.
  • If Proxy-Protocol support is not required, disable or remove it to prevent exploitation until a patch is applied.
  • Add network-level restrictions to block connections from untrusted or attacker-controlled proxies that may send Proxy-Protocol headers.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6522-1 exim4 security update
Ubuntu USN Ubuntu USN USN-8834-1 Exim vulnerabilities
History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Proxy-Protocol in Exim

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
First Time appeared Exim
Exim exim
Weaknesses CWE-787
CPEs cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
Vendors & Products Exim
Exim exim
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T16:07:39.291Z

Reserved: 2026-09-19T22:46:24.165Z

Link: CVE-2026-94054

cve-icon Vulnrichment

Updated: 2026-09-22T16:07:06.281Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-19T23:17:10.827

Modified: 2026-09-24T20:47:34.840

Link: CVE-2026-94054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:16Z

Weaknesses