← back
CVE-2026-40685mediumCWE-684

CVE-2026-40685

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
In short

Exim email servers with JSON lookup enabled can crash or be compromised if they receive emails with malformed JSON in headers. An attacker can exploit incorrect handling of backslashes to write data outside memory boundaries.

Technical detail

An out-of-bounds heap write vulnerability exists in Exim's JSON lookup operator when processing malformed JSON from untrusted email headers, caused by flawed backslash escaping logic. The attack requires JSON lookup to be enabled and attacker control over email headers, potentially allowing memory corruption and code execution.

Summary generated and translated by AI from the official description.
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected products
Exim · Exim