CVE-2026-40685: medium-severity vulnerability in Exim
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
In short
Exim email servers with JSON lookup enabled can crash or be compromised if they receive emails with malformed JSON in headers. An attacker can exploit incorrect handling of backslashes to write data outside memory boundaries.
Technical detail
An out-of-bounds heap write vulnerability exists in Exim's JSON lookup operator when processing malformed JSON from untrusted email headers, caused by flawed backslash escaping logic. The attack requires JSON lookup to be enabled and attacker control over email headers, potentially allowing memory corruption and code execution.
Summary generated and translated by AI from the official description.
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected products
Exim · EximRelated CVEs — Exim
In the same product, most dangerous first.
CVE-2025-26794HIGHCVE-2025-26794EPSS 77.6%CVE-2023-42114LOWExim NTLM Challenge Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 26.9%CVE-2023-42115CRITICALExim AUTH Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 12.1%CVE-2023-42117HIGHExim Improper Neutralization of Special Elements Remote Code Execution VulnerabilityEPSS 6.8%CVE-2023-42116HIGHExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 3.8%CVE-2023-42119LOWExim dnsdb Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 1.6%