Exim Mail Server Flaws Enable SMTP Smuggling, Heap Corruption and Data Leakage
Brief
Exim has released version 4.
- 1 to address four security vulnerabilities affecting its mail transfer agent , including SMTP smuggling, heap corruption, stack-data leakage, and a use-after-free condition.
The security release, announced on September 18, 2026, fixes issues tracked under four GCVE identifiers.
Two high-severity vulnerabilities affect Exim’s handling of Proxy Protocol traffic, while a medium-severity SMTP smuggling flaw impacts all Exim versions through 4.100.
Exim Mail Server Flaws
The most serious issue, GCVE-25-2026-09-50-1, is an out-of-bounds write and heap-corruption vulnerability in Proxy Protocol v1 handling. It affects Exim releases from version 4. 83 through 4. 100 when the server is built and configured to use Proxy Protocol.
