Input validation error in Exim - CVE-2026-94057
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to submit a message different from the one sent and logged by the sending system.
The vulnerability exists due to improper message termination handling in SMTP reception when processing message data after a data-phase rejection. A remote attacker can send a message with crafted data following the rejection point to submit a message different from the one sent and logged by the sending system.
Normal configured processing for received messages is applied to the smuggled message.
Affected software
Debian Linux
exim4 (Debian package)
How to mitigate CVE-2026-94057
exim4 (Debian package) - update to 4.98.2-1+deb13u5