CVE-2026-94055: Use After Free
Published Sep 19, 2026
·Updated
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Affected Software
1 affected component
Exim Exim<4.100.1
Event History
Sep 19, 2026
CVE Published
via MITRE·10:48 PM
Data Sourced
via MITRE·10:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Affected deployments are Exim versions before 4.100.1 that use GnuTLS with certain non-default TLS settings. The provided information does not identify the specific settings.
2
Can this be exploited remotely without authentication or user interaction?
The vector is network-based, and the CVSS data indicates no privileges or user interaction are required. Exploitation is rated high complexity.
3
What is the expected impact?
The stated impact is limited to availability; confidentiality and integrity impacts are listed as none. The CVSS score is 3.7 (low).
4
What should be prioritized for remediation?
Upgrade affected Exim installations to 4.100.1 or later. Prioritize systems using GnuTLS and the applicable non-default TLS configuration.