Title: Exim Security Advisory for EXIM-Security-2026-09-12.4 / GCVE-25-2026-09-56-1 Announced: 2026-09-18 Affects: All Exim versions up to and including 4.100 Corrected: Exim 4.100.1 Reported ref: WT-2026-0148 Exim Security Vulnerability: EXIM-Security-2026-09-12.4 ======================================================= Identifier: EXIM-Security-2026-09-12.4 (GCVE-25-2026-09-56-1) Area: SMTP reception Type: SMTP smuggling Severity: Medium Credit: McCaulay Hudson (@_McCaulay) of watchTowr Timeline -------- 2026-09-08 13:46 UTC Report received 2026-09-11 12:53 UTC Fix drafted 2026-09-11 18:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/) 2026-09-12 12:00 UTC Fix branch and tag exim-4.100.1 pushed to exim-distros 2026-09-18 12:00 UTC Public release Vulnerability Summary --------------------- A remote attacker can cause a message submission different to the one sent and logged by the sending system. The attack requires a data-phase rejection of a message which has crafted data following the rejection point. Note hoever that the normal and configured procesing done for recived messages is applied to the "smuggled" message. Affected Systems ---------------- - All Exim versions up to and including 4.100 are affected. Mitigation ---------- (None) Resolution ---------- The issue is resolved in Exim version 4.100.1. All users of affected versions are strongly encouraged to upgrade. The fix properly identifies the end of data phase, for a rejection. Downloads --------- The new version is available from the usual locations: - https://ftp.exim.org/pub/exim/exim4/ - https://code.exim.org/exim/exim (branch master, tag exim-4.100.1) The release tag exim-4.100.1, signed by Jeremy Harris , key xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx