CVE-2025-26794
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
- Affected products
- Astra Linux, Exim, Red Os
- Exim
- < 4.98.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 77.2% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2025-02-21
CVE-2025-26794 at NVD
9 known exploits for CVE-2025-26794
Proof-of-concept code and exploit modules indexed by Sploitus