Vulnerability record · CVE-2026-45185 · published 12 May 2026
CVE-2026-45185: Exim use after free vulnerability
Exim · Exim
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
Description
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://code.exim.org/exim/wiki/wiki/EximSecurity | Vendor Advisory |
| https://exim.org | Product |
| https://exim.org/static/doc/security/CVE-2026-45185.txt | Broken Link |
| https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/ | Release Notes |
| https://news.ycombinator.com/item?id=48111748 | Issue Tracking |
| https://www.openwall.com/lists/oss-security/2026/05/12/4 | Mailing ListThird Party Advisory |
| https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/12/25 | Mailing ListThird Party Advisory |
Track CVE-2026-45185 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-45185), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.