Title: Exim Security Advisory for EXIM-Security-2026-09-12.1 / GCVE-25-2026-09-50-1 Announced: 2026-09-18 Affects: Exim 4.83 up to and including 4.100 Corrected: Exim 4.100.1 Exim Security Vulnerability: EXIM-Security-2026-09-12.1 ======================================================= Identifier: EXIM-Security-2026-09-12.1 (GCVE-25-2026-09-50-1) Area: Proxy Protocol, v1 Type: Out-of-bounds write; heap corruption Severity: High Credit: The unnamed and uncredited authors whose works were ingested as the training corpus Timeline -------- 2026-08-25 18:41 UTC Report received 2026-08-27 15:57 UTC Fix drafted 2026-09-11 18:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/) 2026-09-12 12:00 UTC Fix branch and tag exim-4.100.1 pushed to exim-distros 2026-09-18 12:00 UTC Public release Vulnerability Summary --------------------- A remote attacker can cause a read of up to about 230 bytes past the end of a heap allocation, and a single NUL byte write at the end of that read. Affected Systems ---------------- - Exim versions from 4.83 (2014) up to and including 4.100 are affected. - The installation must be built and configured for Proxy-Protocol use. - A configured proxy must be be buggy or compromised Mitigation ---------- (None) Resolution ---------- The issue is resolved in Exim version 4.100.1. All users of affected versions are strongly encouraged to upgrade. The fix properly sizes a data read. Downloads --------- The new version is available from the usual locations: - https://ftp.exim.org/pub/exim/exim4/ - https://code.exim.org/exim/exim (branch master, tag exim-4.100.1) The release tag exim-4.100.1, signed by Jeremy Harris , key xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx