Exim 4.100.1 Released: Four Vulnerabilities Patched with No Workarounds
Exim maintainers released 4.100.1 on 2026-09-18, a security patch fixing four vulnerabilities that span heap corruption, a use-after-free bug, a stack-data leak, and SMTP smuggling. Two of the flaws were reported by watchTowr's McCaulay Hudson, while the other two earned Exim's signature joke credit line blaming AI training data. Because the Proxy Protocol and SMTP-smuggling issues affect versions from 4.83 (2014) all the way through 4.100, a huge installed base of production mail servers is at risk. Three of the four flaws have no workaround, so the project's advice is blunt: upgrade to 4.100.1.
Exim 4.100.1 Released: Four Vulnerabilities Patched with No Workarounds @ Linux Compatible
Exim 4.100.1 Released: Four Vulnerabilities Patched with No Workarounds
Exim has released version 4.100.1, addressing four vulnerabilities related to heap corruption, a use-after-free bug, a stack-data leak, and SMTP smuggling, with no workarounds for three of them. The vulnerabilities affect a wide range of Exim versions, from 4.83 (2014) to 4.100, putting many production mail servers at risk. The Exim Project has opted to track these issues using their own Global CVE Allocation System rather than the traditional MITRE CVE program. Due to the severity of the flaws, especially the heap over-read and stack leak, users are strongly advised to upgrade to 4.100.1 to mitigate risks
