PT-2026-36197 · Exim+3 · Exim+3

·

CVE-2026-40686

·

Published

2026-03-23

·

Updated

2026-07-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.99.2
Description An out-of-bounds read occurs when utf8 operators are enabled and malformed UTF-8 header data containing large UTF-8 trailing characters is processed. This issue may allow a remote attacker to cause sensitive information to be disclosed within an error message generated during the handling of an unrelated e-mail message.
Recommendations Update to version 4.99.2 or later. As a temporary workaround, disable utf8 operators to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09404
CVE-2026-40686
USN-8228-1
USN-8382-1

Affected Products

Exim
Linuxmint
Red Os
Ubuntu