LeakyCreds
NewInstant webhook alerts now available โ€” notified within seconds of any credential detection.Learn more โ†’
Home / Vulnerability Intelligence / CVE-2026-45185

CVE-2026-45185 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: May 12, 2026

Published: May 12, 2026Updated: May 12, 2026PoC AvailableRemote Exploitable

Overview

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Social Media Activity(11 posts)

HackerNews
HackerNews
@newsycombinator
May 12, 2026

Dead.Letter (CVE-2026-45185) โ€“ How XBOW found an unauthenticated RCE on Exim Link: https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim Comments: https://news.ycombinator.com/item?id=48111748

View original post
HackNews Bot
HackNews Bot
@hnbot
May 12, 2026

Dead.letter (CVE-2026-45185) Humans vs. LLM for Unauthenticated RCE Race on Exim - https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim #hackernews

View original post
N-gated Hacker News
N-gated Hacker News
@ngate
May 12, 2026

๐Ÿš€ Ah, another day, another #CVE nobody asked for. Humans vs. #AI in a race to exploit #Exim, because *obviously* that's what we needโ€”Skynet learning to hack email servers. ๐Ÿ˜‚ But hey, at least the buzzwords and pentest pitches are here to save us from the tedium of actual #security work. ๐Ÿ“‰ https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim #Skynet #Hacking #HackerNews #ngated

View original post
Hacker News
Hacker News
@h4ckernews
May 12, 2026

Dead.letter (CVE-2026-45185) Humans vs. LLM for Unauthenticated RCE Race on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim #HackerNews #DeadLetter #CVE202645185 #UnauthenticatedRCE #Exim #LLMVsHumans

View original post
Curated Hacker News
Curated Hacker News
@CuratedHackerNews
May 12, 2026

Dead.Letter (CVE-2026-45185) โ€“ How XBOW found an unauthenticated RCE on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

View original post
/r/netsec
/r/netsec
@_r_netsec
May 12, 2026

Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

View original post
HackerNews
HackerNews
@newsycombinator
May 12, 2026

Dead.Letter (CVE-2026-45185) โ€“ How XBOW found an unauthenticated RCE on Exim Link: https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim Comments: https://news.ycombinator.com/item?id=48111748

View original post
N-gated Hacker News
N-gated Hacker News
@ngate
May 12, 2026

๐Ÿš€ Ah, another day, another #CVE nobody asked for. Humans vs. #AI in a race to exploit #Exim, because *obviously* that's what we needโ€”Skynet learning to hack email servers. ๐Ÿ˜‚ But hey, at least the buzzwords and pentest pitches are here to save us from the tedium of actual #security work. ๐Ÿ“‰ https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim #Skynet #Hacking #HackerNews #ngated

View original post
Hacker News
Hacker News
@h4ckernews
May 12, 2026

Dead.letter (CVE-2026-45185) Humans vs. LLM for Unauthenticated RCE Race on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim #HackerNews #DeadLetter #CVE202645185 #UnauthenticatedRCE #Exim #LLMVsHumans

View original post
Curated Hacker News
Curated Hacker News
@CuratedHackerNews
May 12, 2026

Dead.Letter (CVE-2026-45185) โ€“ How XBOW found an unauthenticated RCE on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

View original post
/r/netsec
/r/netsec
@_r_netsec
May 12, 2026

Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

View original post

Details

CVE ID
CVE-2026-45185
Severity
Critical
CVSS Score
9.8
Status
new
EPSS
0.0%
Social Posts
11

CWE

  • CWE-416

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days