Logo
vulnerabilityCVE-2026-45185
Name
CVE-2026-45185
Source
NVD ( link)Debian ( link)
Description
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
exim
Exploitable

Vulnerability Ratings#


9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.99.4
Not Affected
buildroot
master
4.99.4
Not Affected
openwrt
master
4.99.4-r1
Not Affected