7.5

CVE-2026-94056

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exim ≫ Exim Version < 4.100.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.161
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
MITRE 7.5 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html
Vendor Advisory