Title: Exim Security Advisory for EXIM-Security-2026-09-12.2 / GCVE-25-2026-09-55-1 Announced: 2026-09-18 Affects: Exim 4.83 up to and including 4.100 Corrected: Exim 4.100.1 Reporter ref: WT-2026-0149 Exim Security Vulnerability: EXIM-Security-2026-09-12.2 ======================================================= Identifier: EXIM-Security-2026-09-12.2 (GCVE-25-2026-09-55-1) Area: Proxy Protocol, v2 Type: Use of uninitialised data Severity: High Credit: McCaulay Hudson (@_McCaulay) of watchTowr Timeline -------- 2026-09-08 13:48 UTC Report received 2026-09-10 14:52 UTC Fix drafted 2026-09-11 18:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/) 2026-09-12 12:00 UTC Fix branch and tag exim-4.100.1 pushed to exim-distros 2026-09-18 12:00 UTC Public release Vulnerability Summary --------------------- A remote attacker can cause a leak of stack data to be transmitted. Affected Systems ---------------- - Exim versions from 4.83 (2014) up to and including 4.100 are affected. - The installation must be built and configured for Proxy-Protocol use. - A configured proxy must be be buggy or compromised Mitigation ---------- (None) Resolution ---------- The issue is resolved in Exim version 4.100.1. All users of affected versions are strongly encouraged to upgrade. The fix repeats reads until a complete protocol header is received. Downloads --------- The new version is available from the usual locations: - https://ftp.exim.org/pub/exim/exim4/ - https://code.exim.org/exim/exim (branch master, tag exim-4.100.1) The release tag exim-4.100.1, signed by Jeremy Harris , key xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx