Vulnerability Description
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | >= 4.97, < 4.99.3 |
Related Weaknesses (CWE)
References
- https://code.exim.org/exim/wiki/wiki/EximSecurityVendor Advisory
- https://exim.orgProduct
- https://exim.org/static/doc/security/CVE-2026-45185.txtBroken Link
- https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/Release Notes
- https://news.ycombinator.com/item?id=48111748Issue Tracking
- https://www.openwall.com/lists/oss-security/2026/05/12/4Mailing ListThird Party Advisory
- https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-eximThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/05/12/25Mailing ListThird Party Advisory
FAQ
What is CVE-2026-45185?
CVE-2026-45185 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CH...
How severe is CVE-2026-45185?
CVE-2026-45185 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45185?
Check the references section above for vendor advisories and patch information. Affected products include: Exim Exim.