← back
CVE-2026-48840mediumCWE-839

CVE-2026-48840

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
In short

Exim mail server versions before 4.99.4 can leak uninitialized memory to clients in certain proxy setups when processing short payloads. This could expose sensitive data that was previously stored in the server's memory.

Technical detail

A memory disclosure vulnerability in Exim 4.88–4.99.3 occurs when specific proxy configurations process crafted short payloads, causing uninitialized stack memory to be returned to an unauthenticated client. Attack requires a susceptible proxy setup; impact is information disclosure of potentially sensitive in-memory data.

Summary generated and translated by AI from the official description.
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Exim · Exim