← Back to browse · API

CVE-2025-26794

Severity
HIGH
CVSS
7.5
EPSS
0.77173
Risk score
57.01
CISA KEV
No
PoC
No
Published
2025-02-21
Modified
2025-12-18
First seen
2026-08-07
Aliases
EUVD-2025-4451, GHSA-V8M7-99RG-XP5C
Products
exim:exim 4.98 <4.98.1
Sources
euvd EUVD-2025-4451

Description

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

References