Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4615-1 | exim4 security update |
Debian DSA |
DSA-6309-1 | exim4 security update |
Fri, 05 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 May 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 30 May 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Exim Proxy Misconfiguration Causes Uninitialized Memory Disclosure |
Sat, 30 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. | |
| First Time appeared |
Exim
Exim exim |
|
| Weaknesses | CWE-839 | |
| CPEs | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Exim
Exim exim |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-05T09:07:37.892Z
Reserved: 2026-05-25T17:51:46.146Z
Link: CVE-2026-48840
Updated: 2026-06-05T09:07:37.892Z
Status : Modified
Published: 2026-05-30T02:16:19.790
Modified: 2026-06-05T11:16:36.677
Link: CVE-2026-48840
No data.
OpenCVE Enrichment
Updated: 2026-05-30T04:00:09Z
Debian DLA
Debian DSA