CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
- Exim
- < 4.99.3
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2026-05-12
CVE-2026-45185 at NVD
2 known exploits for CVE-2026-45185
Proof-of-concept code and exploit modules indexed by Sploitus