← back
CVE-2026-40687mediumCWE-909

CVE-2026-40687

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.8epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

Exim email server has a flaw in its SPA authentication method that can crash connections or leak sensitive data from memory when processing specially crafted authentication requests.

Technical detail

An out-of-bounds write vulnerability exists in Exim's SPA authentication driver (CWE-909) when processing adversarial SPA resources, enabling denial of service via connection crash or information disclosure through uninitialized heap memory access. Exploitation requires sending a malformed SPA authentication request to an Exim instance configured with SPA driver enabled.

Summary generated and translated by AI from the official description.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected products
Exim · Exim