Junglewise Threat Intelligence

CVE-2026-94054: Exim out-of-bounds write in Proxy Protocol v1

CVE-2026-94054 · Severity: high · CVSS 7 · Published 2026-09-19

Technologies: Exim. Vendors: Exim.

Executive brief

Exim is a widely used mail transfer agent that processes incoming email. When configured to accept connections through a proxy using Proxy Protocol v1, a remote attacker controlling the proxy can trigger an out-of-bounds write on the heap, causing memory corruption that could lead to data exposure or system compromise.

Technical details

An out-of-bounds write vulnerability in Exim's Proxy Protocol v1 handling allows a remote attacker to write a NUL byte past the end of a heap allocation during packet processing. The vulnerability requires Exim to be built with Proxy Protocol support and configured to use it, and the proxy must be buggy or compromised. The fix properly sizes the data read operation to prevent the overflow.

Affected products

  • Exim Exim 4.83 to 4.100, fixed in 4.100.1

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Exim 4.100.1 released

References

Related threats