Exim
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Exim.
Known Exploited Exim Vulnerabilities
The following Exim vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Exim Privilege Escalation Vulnerability |
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. CVE-2010-4345 Exploit Probability: 18.0% |
March 25, 2022 |
| Exim Heap-Based Buffer Overflow Vulnerability |
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. CVE-2010-4344 Exploit Probability: 71.7% |
March 25, 2022 |
| Exim Buffer Overflow Vulnerability |
Issue in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely. CVE-2018-6789 Exploit Probability: 82.1% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2010-4345: Exim Privilege Escalation Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
Exim EOL Dates
Ensure that you are using a supported version of Exim. Here are some end of life, and end of support dates for Exim.
| Release | EOL Date | Status |
|---|---|---|
| 4.99 | - |
Active
|
| 4.98 | October 28, 2025 |
EOL
Exim 4.98 became EOL in 2025. |
| 4.97 | July 10, 2024 |
EOL
Exim 4.97 became EOL in 2024. |
| 4.96 | November 4, 2023 |
EOL
Exim 4.96 became EOL in 2023. |
| 4.95 | June 25, 2022 |
EOL
Exim 4.95 became EOL in 2022. |
| 4.94 | September 28, 2021 |
EOL
Exim 4.94 became EOL in 2021. |
| 4.93 | June 1, 2020 |
EOL
Exim 4.93 became EOL in 2020. |
| 4.92 | December 8, 2019 |
EOL
Exim 4.92 became EOL in 2019. |
| 4.91 | February 10, 2019 |
EOL
Exim 4.91 became EOL in 2019. |
| 4.90 | April 15, 2018 |
EOL
Exim 4.90 became EOL in 2018. |
| 4.89 | December 19, 2017 |
EOL
Exim 4.89 became EOL in 2017. |
| 4.88 | March 7, 2017 |
EOL
Exim 4.88 became EOL in 2017. |
| 4.87 | December 18, 2016 |
EOL
Exim 4.87 became EOL in 2016. |
| 4.86 | April 6, 2016 |
EOL
Exim 4.86 became EOL in 2016. |
| 4.85 | July 26, 2015 |
EOL
Exim 4.85 became EOL in 2015. |
| 4.84 | January 12, 2015 |
EOL
Exim 4.84 became EOL in 2015. |
| 4.83 | August 11, 2014 |
EOL
Exim 4.83 became EOL in 2014. |
| 4.82 | July 21, 2014 |
EOL
Exim 4.82 became EOL in 2014. |
| 4.80 | October 28, 2013 |
EOL
Exim 4.80 became EOL in 2013. |
| 4.77 | May 31, 2012 |
EOL
Exim 4.77 became EOL in 2012. |
By the Year
In 2026 there have been 12 vulnerabilities in Exim with an average score of 6.2 out of ten. Last year, in 2025 Exim had 4 security vulnerabilities published. That is, 8 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 1.08
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 12 | 6.17 |
| 2025 | 4 | 7.25 |
| 2024 | 6 | 0.00 |
| 2023 | 1 | 0.00 |
| 2022 | 4 | 7.93 |
| 2021 | 22 | 8.22 |
| 2020 | 1 | 0.00 |
| 2019 | 4 | 9.80 |
| 2018 | 1 | 9.80 |
It may take a day or so for new Exim vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Exim Security Vulnerabilities
Exim <4.100.1 SMTP Smuggling via DATA Rejection
CVE-2026-94057
4 - Medium
- September 19, 2026
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CRLF Injection
Exim <4.100.1: Proxy-Protocol Uninit Stack Data Leak
CVE-2026-94056
7.5 - High
- September 19, 2026
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Use of Uninitialized Resource
Exim <4.100.1 Use-After-Free via GnuTLS TLS Settings
CVE-2026-94055
3.7 - Low
- September 19, 2026
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Dangling pointer
Exim <4.100.1 OOB Write via Proxy-Protocol (attacker-controlled IP)
CVE-2026-94054
7 - High
- September 19, 2026
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Memory Corruption
Exim <4.99.5 .forward Priv Escalation via Pipe Force_Command Mishandling
CVE-2026-66141
7.4 - High
- July 24, 2026
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Inclusion of Functionality from Untrusted Control Sphere
Exim <4.99.5 Directory Traversal via Queue-Name args
CVE-2026-66140
8.4 - High
- July 24, 2026
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
Path Traversal: '../filedir'
Exim 4.88-4.99.4 Proxy bug discloses uninit stack memory
CVE-2026-48840
5.3 - Medium
- May 30, 2026
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
Signed comparison
Exim <4.99.3 Use-After-Free in BDAT body parsing via TLS close_notify
CVE-2026-45185
9.8 - Critical
- May 12, 2026
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
Dangling pointer
Exim <4.99.2 SPA Auth OOB Write & Data Leak
CVE-2026-40687
4.8 - Medium
- April 30, 2026
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Missing Initialization of Resource
Exim <4.99.2 UTF-8 OOB Read with large trailing chars
CVE-2026-40686
3.7 - Low
- April 30, 2026
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
Out-of-bounds Read
Exim <4.99.2 Heap OOB in JSON Lookup due to Malformed Header
CVE-2026-40685
6.5 - Medium
- April 30, 2026
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
Incorrect Provision of Specified Functionality
Exim <=4.99.1 Crash on musl via malformed DNS PTR (dn_expand)
CVE-2026-40684
5.9 - Medium
- April 30, 2026
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
Incorrect Provision of Specified Functionality
Exim <4.99.1 Remote Heap Corruption
CVE-2025-67896
7 - High
- December 14, 2025
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Heap-based Buffer Overflow
Exim logrotate Symlink Following P8 Escalation before 4.98.2
CVE-2025-53881
- October 02, 2025
A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.
Symlink following
Use-After-Free in Exim 4.96-4.98.1 Allows Privilege Escalation
CVE-2025-30232
- March 28, 2025
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
Exim 4.98<4.98.1 Remote SQLi via SQLite Hints & ETRN
CVE-2025-26794
7.5 - High
- February 21, 2025
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
SQL Injection
Exim <=4.97.1 RFC2231 Header Filename Parsing Bypass Allows Exec Attachments
CVE-2024-39929
- July 04, 2024
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Exim AUTH OOB Write RCE Vulnerability
CVE-2023-42115
- May 03, 2024
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.
Exim SMTP NTLM Challenge Stack Buffer Overflow RCE
CVE-2023-42116
- May 03, 2024
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.
Stack Overflow
Exim SMTP RCE: Improper Neutralization Leads to Remote Execution
CVE-2023-42117
- May 03, 2024
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.
Improper Neutralization of Special Elements
Exim dnsdb OOB Read Info Disclosure in SMTP Service
CVE-2023-42119
- May 03, 2024
Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.
Out-of-bounds Read
Exim NTLM Challenge OOB Read Info Disclosure
CVE-2023-42114
- May 03, 2024
Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.
Out-of-bounds Read
Exim <4.97.1: SMTP Smuggling bypass SPF via PIPELINING/CHUNKING
CVE-2023-51766
- December 24, 2023
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
Exim DMARC Handler use-after-free in dmarc_dns_lookup
CVE-2022-3620
9.8 - Critical
- October 20, 2022
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919.
Buffer Overflow
Exim RegexHandler UAF in Regex Processing
CVE-2022-3559
4.6 - Medium
- October 17, 2022
A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
Buffer Overflow
Exim <4.95 Heap Buffer Overflow in host_name_lookup (alias list)
CVE-2022-37452
9.8 - Critical
- August 07, 2022
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
Memory Corruption
Exim <4.96: Invalid Free in pam_converse (store_free missing)
CVE-2022-37451
7.5 - High
- August 06, 2022
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Release of Invalid Pointer or Reference
The STARTTLS feature in Exim through 4.94.2
CVE-2021-38371
- August 10, 2021
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges
CVE-2020-28007
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.
insecure temporary file
Exim 4 before 4.94.2 has Execution with Unnecessary Privileges
CVE-2021-27216
6.3 - Medium
- May 06, 2021
Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.
Improper Privilege Management
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges
CVE-2020-28008
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.
Improper Privilege Management
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations
CVE-2020-28026
9.8 - Critical
- May 06, 2021
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.
Exim 4 before 4.94.2
CVE-2020-28025
7.5 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.
Out-of-bounds Read
Exim 4 before 4.94.2 allows Buffer Underwrite
CVE-2020-28024
9.8 - Critical
- May 06, 2021
Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc was only intended to push back characters, but can actually push back non-character error codes such as EOF.
Buffer Overflow
Exim 4 before 4.94.2 allows Out-of-bounds Read
CVE-2020-28023
7.5 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP client.
Out-of-bounds Read
Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer
CVE-2020-28022
9.8 - Critical
- May 06, 2021
Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs within MAIL FROM and RCPT TO commands.
Buffer Overflow
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters
CVE-2020-28021
8.8 - High
- May 06, 2021
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newline characters into a spool file (which indirectly leads to remote code execution as root) via AUTH= in a MAIL FROM command.
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in
CVE-2020-28020
9.8 - Critical
- May 06, 2021
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.
Integer Overflow or Wraparound
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences
CVE-2020-28019
7.5 - High
- May 06, 2021
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.
Improper Initialization
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations
CVE-2020-28018
9.8 - Critical
- May 06, 2021
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
Dangling pointer
Exim 4 before 4.94.2
CVE-2020-28016
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.
Memory Corruption
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters
CVE-2020-28015
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges
CVE-2020-28014
6.1 - Medium
- May 06, 2021
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.
Improper Privilege Management
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '
CVE-2020-28013
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.
Memory Corruption
Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe
CVE-2020-28012
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe that lacks a close-on-exec flag.
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S
CVE-2020-28011
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim to root.
Memory Corruption
Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer
CVE-2020-28010
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer that is too small (on some common platforms).
Memory Corruption
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads
CVE-2020-28009
7.8 - High
- May 06, 2021
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increases in a certain size variable. NOTE: exploitation may be impractical because of the execution time needed to overflow (multiple days).
Integer Overflow or Wraparound
Exim 4 before 4.94.2
CVE-2020-28017
9.8 - Critical
- May 06, 2021
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.
Integer Overflow or Wraparound
Exim through 4.93 has an out-of-bounds read in the SPA authenticator
CVE-2020-12783
- May 11, 2020
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.