cvedb.io
CVE-2025-26794
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2025-02-21T13:15:11.687 · Last modified 2026-06-17T09:02:26.890

Summary

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

Affected products

exim — exim

Does this affect you?

Add your gear to cvedb and we'll alert you only when exim ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.