Exim 4.100.1 fixes high-severity Proxy Protocol heap bug
The mail transfer agent closes four flaws dating to 2014, with no workaround short of upgrading.
Exim maintainers have released version 4.100.1 to fix four security vulnerabilities in the open-source mail transfer agent.
The standout issue, GCVE-25-2026-09-50-1, is a high-severity out-of-bounds write and heap corruption flaw in Proxy Protocol v1 handling. A remote attacker can read up to about 230 bytes past the end of a heap allocation and write a single NUL byte at the end of that read. Exposure requires Exim built and configured for Proxy Protocol, plus a buggy or compromised fronting proxy. Versions from 4.83 (2014) through 4.100 are affected. The maintainers list no mitigation other than upgrading.
The same release also resolves GCVE-25-2026-09-51-1, GCVE-25-2026-09-55-1, and GCVE-25-2026-09-56-1. Users of affected versions are strongly encouraged to move to 4.100.1.