Exim: pre-authentication stack leak

CVE-2026-48840

Public research by Warisjeet Singh sin99xx

Disclosed

The public finding

What was found.

Malformed PROXY frames can disclose live stack bytes before SMTP authentication when the sender is trusted by hosts_proxy, exposing an ASLR-defeat primitive.

Sources and evidence.

read the advisory ↗
The evidence: the advisory, verbatim
exim.org · EXIM-Security-2026-05-19.1 coordinated release 2026-05-29
Identifier:   EXIM-Security-2026-05-19.1 (CVE-2026-48840)
Type:         Pre-authentication information disclosure (uninitialised stack)
Severity:     Moderate (CVSS 5.3)
Credit:       Warisjeet Singh (sin99xx)

2026-05-19 12:35 UTC: Initial security report received from Warisjeet Singh (sin99xx).
2026-05-19 13:26 UTC: Exim maintainers acknowledge the report.
2026-05-19 14:06 UTC: Root cause confirmed; fix prepared in private repositories.
2026-05-29 14:00 UTC: Public coordinated release of the fix and advisory.