CVE-2025-26794

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
21/02/2025
Last modified:
18/12/2025

Description

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* 4.98 (including) 4.98.1 (excluding)