CVE Vulnerabilities

CVE-2026-40685

Incorrect Provision of Specified Functionality

Published: Apr 30, 2026 | Modified: May 01, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of skipping.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.99.2 (excluding)
Exim4Ubuntudevel*
Exim4Ubuntuesm-infra-legacy/trusty*
Exim4Ubuntuesm-infra-legacy/xenial*
Exim4Ubuntuesm-infra/bionic*
Exim4Ubuntuesm-infra/focal*
Exim4Ubuntuesm-infra/xenial*
Exim4Ubuntujammy*
Exim4Ubuntunoble*
Exim4Ubuntuquesting*
Exim4Ubunturesolute*
Exim4Ubuntuupstream*

Potential Mitigations

References