CVE-2026-40687 Details
Description
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
A vulnerability in Exim versions prior to 4.99.2 allows for an out-of-bounds write when the SPA authentication driver is used with a malicious SPA resource. This can lead to a crash of the connection instance or cause erroneous data processing that exposes information from uninitialized heap memory.
Users can upgrade to Exim version 4.99.2, available as a tarball from the Exim FTP site or directly from Git. Instructions for verifying the release signature are also provided.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code.exim.org/exim/exim/commit/68b963b9f75ca27b38e1c0f8c87037990199f505 | [email protected] | Patch |
| https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40687.assessment | [email protected] | Vendor Advisory |
| https://exim.org/static/doc/security/CVE-2026-40687.txt | [email protected] | Broken Link |
| https://www.openwall.com/lists/oss-security/2026/04/30/21 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-909 | Missing Initialization of Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| exim exim | < 4.99.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | New CVE Received | [email protected] |