CVE-2026-40687
MEDIUM
NVD
CVSS Score
4.8
Severity
MEDIUM
Published
Apr 30, 2026
Vendor
unknown
Description
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.