High severity7.0OSV Advisory· Published Dec 14, 2025· Updated Jun 17, 2026
CVE-2025-67896
CVE-2025-67896
Description
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- exim.org/static/doc/security/nvdVendor Advisory
- exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txtnvdVendor Advisory
- www.openwall.com/lists/oss-security/2025/12/14/1nvdMailing List
- www.openwall.com/lists/oss-security/2025/12/18/3nvdMailing List
- www.openwall.com/lists/oss-security/2025/12/11/2nvdMailing List
News mentions
0No linked articles in our index yet.