Security Advisory

CVE-2026-40685

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-30 00:00:00
Last updated 2026-05-01 14:26:41
Assigner mitre
State PUBLISHED

Description

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of skipping.