CVE-2025-26794

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*

History

18 Dec 2025, 19:16

Type Values Removed Values Added
References
  • () https://exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt -
References () https://bugzilla.suse.com/show_bug.cgi?id=1237424 - Third Party Advisory, Issue Tracking () https://bugzilla.suse.com/show_bug.cgi?id=1237424 - Issue Tracking, Third Party Advisory
Summary (en) Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (en) Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

25 Sep 2025, 13:12

Type Values Removed Values Added
References () https://bugzilla.suse.com/show_bug.cgi?id=1237424 - () https://bugzilla.suse.com/show_bug.cgi?id=1237424 - Third Party Advisory, Issue Tracking
References () https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305 - () https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305 - Patch
References () https://exim.org - () https://exim.org - Product
References () https://github.com/Exim/exim/wiki/EximSecurity - () https://github.com/Exim/exim/wiki/EximSecurity - Vendor Advisory
References () https://github.com/NixOS/nixpkgs/pull/383926 - () https://github.com/NixOS/nixpkgs/pull/383926 - Release Notes
References () https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d - () https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d - Patch
References () https://www.exim.org/static/doc/security/CVE-2025-26794.txt - () https://www.exim.org/static/doc/security/CVE-2025-26794.txt - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/19/1 - () http://www.openwall.com/lists/oss-security/2025/02/19/1 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/21/4 - () http://www.openwall.com/lists/oss-security/2025/02/21/4 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/21/5 - () http://www.openwall.com/lists/oss-security/2025/02/21/5 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
First Time Exim
Exim exim

22 Feb 2025, 01:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/21/4 -
  • () http://www.openwall.com/lists/oss-security/2025/02/21/5 -

21 Feb 2025, 19:15

Type Values Removed Values Added
References
  • () https://bugzilla.suse.com/show_bug.cgi?id=1237424 -
  • () https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305 -
  • () https://github.com/Exim/exim/wiki/EximSecurity -
  • () https://github.com/NixOS/nixpkgs/pull/383926 -
  • () https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d -
Summary
  • (es) Exim 4.98 anterior a la versíon 4.98.1 permite una inyección SQL remota cuando se usan serialización de ETRN con la tabla hints en SQLite.

21 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 13:15

Updated : 2025-12-18 19:16


NVD link : CVE-2025-26794

Mitre link : CVE-2025-26794

CVE.ORG link : CVE-2025-26794


JSON object : View

Products Affected

exim

  • exim
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')