← Back to CVE List
CVE-2026-94057NVD
Vulnerability Summary
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CVSS v3.1 Base Metrics — Score 4.0 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Exim Exim < 4.100.1
- Exim Exim 4.100.1