CVE-2025-26794 Affecting exim4 package, versions <4.98-4


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
77.17% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-EXIM4-8740798
  • published22 Feb 2025
  • disclosed21 Feb 2025

Introduced: 21 Feb 2025

CVE-2025-26794  (opens in a new tab)

How to fix?

Upgrade Debian:unstable exim4 to version 4.98-4 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream exim4 package and not the exim4 package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

CVSS Base Scores

version 3.1