Back to overview

CVE-2026-45185

CRITICAL
9.8
CVSS 3.1
Description
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

Metadata

CVE ID
CVE-2026-45185
State
PUBLISHED
Assigner
mitre
Reserved
2026-05-10 00:00 UTC
Published
2026-05-12 00:00 UTC
Last updated
2026-05-14 03:55 UTC
Primary CWE
CWE-416
CWE-416 Use After Free
Vendor / Product
Exim / Exim
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Exim Exim 4.97 < 4.99.3
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416 Use After Free
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview