CVE-2026-40684

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/04/2026
Last modified:
01/05/2026

Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* 4.99.2 (excluding)