CVE-2026-48840
Modified
Modified - Updated After Analysis
Exim Proxy Configuration Short Payload Memory Disclosure
Publication date: 2026-05-30
Last updated on: 2026-06-05
Assigner: MITRE
Description
Description
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| exim | exim | From 4.88 (inc) to 4.99.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-839 | The product checks a value to ensure that it is less than or equal to a maximum, but it does not also verify that the value is greater than or equal to the minimum. |