https://seclists.org/oss-sec/2026/q2/728: CVE-2026-48840: Exim 4.99.4: PROXY-protocol uninitialised-stack information disclosu
Published May 29, 2026
·Updated
Affected Software
1 affected component
Exim Exim>=4.88<=4.99.3
Frequently Asked Questions
1
What is CVE-2026-48840?
CVE-2026-48840 is a pre-authentication information disclosure vulnerability affecting Exim versions 4.88 through 4.99.3.
2
What is the severity of CVE-2026-48840?
The severity of CVE-2026-48840 is considered critical due to its potential to leak sensitive information.
3
How do I fix CVE-2026-48840?
To fix CVE-2026-48840, upgrade Exim to version 4.99.4 or later.
4
Which versions of Exim are affected by CVE-2026-48840?
CVE-2026-48840 affects Exim versions from 4.88 to 4.99.3.
5
When was CVE-2026-48840 published?
CVE-2026-48840 was published on May 29, 2026.