cvedb.io
CVE-2026-48840
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2026-05-30T02:16:19.790 · Last modified 2026-06-17T10:55:16.753

Summary

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

Affected products

exim — exim

Does this affect you?

Add your gear to cvedb and we'll alert you only when exim ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.