VYPR
Medium severity5.9NVD Advisory· Published Apr 30, 2026· Updated May 1, 2026

CVE-2026-40684

CVE-2026-40684

Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Affected products

1
  • cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
    Range: <4.99.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

1