Back to Database
Status published
High
CVE-2025-26794
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization...
Vulnerability Description
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-26794
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exim.org
- https://github.com/Exim/exim/wiki/EximSecurity
- https://www.exim.org/static/doc/security/CVE-2025-26794.txt
- https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305
- https://bugzilla.suse.com/show_bug.cgi?id=1237424
- https://github.com/NixOS/nixpkgs/pull/383926
- https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d
- https://exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt
More from Exim
View All →CVE-2025-67896
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a...
High
7
CVE-2025-30232
A use-after-free in Exim 4.96 through 4.98.1 could allow users...
High
8.1
CVE-2023-42119
Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability
Low
3.1
CVE-2023-42118
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
High
7.5
CVE-2023-42117
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
High
8.1
Affected Vendor
Exim
View all reports →Affected Software
Exim
Vulnerable Versions:
4.98
Timeline
Official Publish:
February 21st, 2025
Last Modified:
December 18th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H