CVE-2026-94056

7.5

Exim · Exim

Exim versions prior to 4.100.1 are vulnerable to an information disclosure flaw when using the Proxy-Protocol, potentially allowing attackers to read uninitialized stack memory.

Executive summary

A high-severity memory disclosure vulnerability in Exim allows remote attackers to access uninitialized data from stack memory when Proxy-Protocol is enabled.

Vulnerability

This vulnerability is a use of uninitialized resource (CWE-908) triggered when the Proxy-Protocol is utilized with an attacker-controlled proxy. The vulnerability is exploitable by unauthenticated remote attackers.

Business impact

Successful exploitation of this flaw allows an attacker to read sensitive data residing in the server's stack memory. Given the CVSS score of 7.5, this high-severity issue poses a significant risk of data leakage, which could expose credentials, session tokens, or other private information processed by the mail server, potentially facilitating further unauthorized access or system compromise.

Remediation

Immediate Action: Upgrade the Exim installation to version 4.100.1 or later as specified in the official vendor release.

Proactive Monitoring: Monitor mail server logs and network traffic for anomalous Proxy-Protocol headers or unusual connection patterns from untrusted proxy sources.

Compensating Controls: If an immediate upgrade is not feasible, restrict the use of the Proxy-Protocol to known, trusted proxies and ensure that infrastructure-level firewalls limit access to the Exim service.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

The vulnerability represents a significant risk to the confidentiality of data processed by the Exim mail server. IT administrators should prioritize the deployment of version 4.100.1 to eliminate the risk of stack memory exposure. Immediate patching is the only definitive way to secure the affected software against potential exploitation attempts.

More Exim CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources