CyberRota Analysis
AI-GeneratedExim versions prior to 4.100.1 are vulnerable when using Proxy-Protocol with an attacker-controlled proxy, enabling attackers to access uninitialized stack memory data. This could lead to information disclosure, potentially exposing sensitive data. Organizations using affected Exim versions, particularly those implementing Proxy-Protocol, should prioritize patching to mitigate this high-severity risk.
CVE
CVE-2026-94056
Severity
HIGH
CVSS
7.5
EPSS
0.36%
Original NVD Description
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Related CVEs
Other vulnerabilities affecting the same vendor(s)