Exim maintainers disclosed and fixed CVE-2026-48840, a pre-authentication information disclosure flaw in Exim’s PROXY protocol handling that affects versions 4.88 through 4.99.3 and is fixed in 4.99.4. The bug is triggered during SMTP HELO/greeting processing when Exim parses a specially crafted PROXYv2 header with insufficient length, causing uninitialized stack data to be copied into an IP address string and exposed in the SMTP banner. Advisories say the leak can disclose 16 bytes on TCPv6 or 4 bytes on TCPv4, including userspace pointers that could help attackers bypass ASLR and support further exploitation.
The issue affects deployments built with SUPPORT_PROXY and configured with a non-empty hosts_proxy value, a combination reported as enabled by default in some downstream builds including Debian, Ubuntu, RHEL EPEL, and Fedora. Exim said exposure is highest where attackers can reach the service from trusted proxy IPs or through a trusted proxy path, and recommended upgrading to 4.99.4, restricting hosts_proxy to exact load balancer addresses, or disabling PROXY protocol parsing entirely by unsetting that option. Related downstream advisories were also issued by cPanel and Debian for packaged Exim deployments.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA 6309-1 for exim4 in response to the Exim vulnerability. This indicates downstream distribution action to address the issue in Debian packages.
The Exim maintainers' advisory for CVE-2026-48840 was publicly released, describing an uninitialized-stack information disclosure in PROXY protocol handling. The disclosure explained that malformed PROXYv2 frames can leak memory in SMTP greetings, including pointers useful for ASLR bypass.
MITRE assigned CVE-2026-48840 to the Exim PROXY-protocol information disclosure issue. The advisory identifies it as a pre-authentication flaw that can leak stack memory and aid ASLR bypass.
cPanel published a security advisory for CVE-2026-48840 under identifier EXIM-Security-2026-05-19.1. The advisory concerns the Exim vulnerability addressed in the May 2026 security release.
Exim maintainers disclosed that CVE-2026-48840 affects versions 4.88 through 4.99.3 and is fixed in Exim 4.99.4. They recommended upgrading, restricting hosts_proxy to exact trusted proxy IPs, or disabling PROXY protocol parsing.
The vulnerable PROXY protocol handling code associated with CVE-2026-48840 dates back to Exim 4.88. The flaw affects builds using SUPPORT_PROXY together with a non-empty hosts_proxy configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourceopennet.ru
Open sourceopennet.me
Open sourcesupport.cpanel.net
Open sourceseclists.org
Open sourcelists.exim.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.