CVE-2026-94056: High severity Exim Exim vulnerability
Published Sep 19, 2026
·Updated
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Affected Software
1 affected component
Exim Exim<4.100.1
Event History
Sep 19, 2026
CVE Published
via MITRE·10:52 PM
Data Sourced
via MITRE·10:52 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Exim deployments using Proxy-Protocol with an attacker-controlled proxy are exposed. The issue affects Exim versions before 4.100.1.
2
What does an attacker need to exploit this?
The attacker needs network access and an attacker-controlled proxy participating in Proxy-Protocol handling. No privileges or user interaction are required, although exploitation has high attack complexity.
3
What is the impact?
An attacker may read certain uninitialized data from Exim stack memory. The listed impact includes high confidentiality impact and low availability impact, with no integrity impact.