CVE-2026-40686 Details
Description
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
A vulnerability allowing out-of-bounds read has been identified in Exim versions prior to 4.99.2. This issue occurs when UTF-8 operators are enabled and large trailing characters in UTF-8 headers are present, leading to the potential disclosure of heap data. The vulnerability arises from the ${from_utf8:} expansion operator, which, when fed malformed input, can read into the heap. If the extracted data is used in an SMTP rejection message, it could result in unauthorized information being leaked.
Users can upgrade to Exim version 4.99.2, which addresses this vulnerability. This version is available as a tarball from the Exim FTP site or directly from the Exim Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code.exim.org/exim/exim/commit/f2570bde16fb4d4a1242ff363a4c4eecf6372efc | [email protected] | Patch |
| https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40686.assessment | [email protected] | Vendor Advisory |
| https://exim.org/static/doc/security/CVE-2026-40686.txt | [email protected] | Broken Link |
| https://www.openwall.com/lists/oss-security/2026/04/30/21 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| exim exim | < 4.99.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | New CVE Received | [email protected] |