Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 20 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Exim Proxy-Protocol Stack Unintended Data Disclosure |
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | |
| First Time appeared |
Exim
Exim exim |
|
| Weaknesses | CWE-908 | |
| CPEs | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Exim
Exim exim |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-19T22:52:43.612Z
Reserved: 2026-09-19T22:52:43.235Z
Link: CVE-2026-94056
No data.
Status : Received
Published: 2026-09-19T23:17:11.113
Modified: 2026-09-19T23:17:11.113
Link: CVE-2026-94056
No data.
OpenCVE Enrichment
Updated: 2026-09-20T00:45:16Z
Weaknesses