CVE-2026-40684: medium-severity vulnerability in Exim
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In short
Exim email servers using musl libc can crash when receiving malformed DNS data in reverse lookup records, disrupting email delivery for that connection.
Technical detail
A vulnerability in Exim versions before 4.99.2 on musl-based systems allows remote attackers to trigger a denial of service by sending crafted DNS PTR records that exploit a dn_expand handling flaw in octal printing, causing the connection process to crash without requiring authentication.
Summary generated and translated by AI from the official description.
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Exim · EximRelated CVEs — Exim
In the same product, most dangerous first.
CVE-2025-26794HIGHCVE-2025-26794EPSS 77.6%CVE-2023-42114LOWExim NTLM Challenge Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 26.9%CVE-2023-42115CRITICALExim AUTH Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 12.1%CVE-2023-42117HIGHExim Improper Neutralization of Special Elements Remote Code Execution VulnerabilityEPSS 6.8%CVE-2023-42116HIGHExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 3.8%CVE-2023-42119LOWExim dnsdb Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 1.6%
References
https://code.exim.org/exim/exim/commit/628bbaca7672748d941a12e7cd5f0122a4e18c81https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40684.assessmenthttps://exim.org/static/doc/security/CVE-2026-40684.txthttps://www.openwall.com/lists/oss-security/2026/04/30/21http://www.openwall.com/lists/oss-security/2026/05/01/11