- Description
- Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
- Source
- cve@mitre.org
- NVD status
- Modified
- Products
- exim
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- cve@mitre.org
- CWE-839
- Hype score
- Not currently trending
🚨*CVE* CVE-2026-48840 Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. https://t.co/jztOvDb6O4 ----- Traducción: CVE-2026-48840 Exim 4.88 … https://t.co/utmtNgl
@infoflowcloud
30 May 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-48840: Exim: PROXY-protocol uninitialised-stack information disclosure. The leaked bytes are confirmed to be live userspace VA pointers, making this an ASLR-defeat primitive usable as a chain component. Fixed in 4.99.4. https://t.co/XXwJxdi063 https://t.co/6FnuYNlKE1
@sin99xx
30 May 2026
31 Impressions
3 Retweets
3 Likes
3 Bookmarks
0 Replies
2 Quotes
CVE-2026-48840 CVE-2026-48840 https://t.co/HMZtp1rqGD
@VulmonFeeds
29 May 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6B0C501F-93D6-45CB-9F65-F69194F70E05",
"versionEndExcluding": "4.99.4",
"versionStartIncluding": "4.88",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]