CVE DATABASE / CVE-2026-45185
CVE-2026-45185
CVSS 9.8 · CRITICAL
Summary
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
CVSS 3.1 breakdown
| Base score | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | HIGH |
| Availability | HIGH |
Weakness type (CWE)
Affected products
Exim exim
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
Our coverage
References
- https://code.exim.org/exim/wiki/wiki/EximSecurity
- https://exim.org
- https://exim.org/static/doc/security/CVE-2026-45185.txt
- https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/
- https://news.ycombinator.com/item?id=48111748
- https://www.openwall.com/lists/oss-security/2026/05/12/4
- https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
- http://www.openwall.com/lists/oss-security/2026/05/12/25
Data: NIST NVD. NVD last modified 2026-05-28. Always verify against the vendor advisory before acting.