Exim: pre-authentication stack leak
CVE-2026-48840
Public research by Warisjeet Singh sin99xx
Disclosed
The public finding
What was found.
Malformed PROXY frames can disclose live stack bytes before SMTP authentication when the sender is trusted by hosts_proxy, exposing an ASLR-defeat primitive.
Sources and evidence.
The evidence: the advisory, verbatim
exim.org · EXIM-Security-2026-05-19.1
coordinated release 2026-05-29
Identifier: EXIM-Security-2026-05-19.1 (CVE-2026-48840) Type: Pre-authentication information disclosure (uninitialised stack) Severity: Moderate (CVSS 5.3) Credit: Warisjeet Singh (sin99xx) 2026-05-19 12:35 UTC: Initial security report received from Warisjeet Singh (sin99xx). 2026-05-19 13:26 UTC: Exim maintainers acknowledge the report. 2026-05-19 14:06 UTC: Root cause confirmed; fix prepared in private repositories. 2026-05-29 14:00 UTC: Public coordinated release of the fix and advisory.