Exim 4.100.1 fixes four flaws, including Proxy Protocol and SMTP smuggling
On 18 September 2026 the Exim project released version 4.100.1, patching four security defects: two High-severity Proxy Protocol bugs, a GnuTLS use-after-free and an SMTP smuggling issue. The top CVSS score is 7.5, with no confirmed exploitation. Versions 4.83 through 4.100 are affected.
- Proxy Protocol v1 and v2 leak memory when a faulty proxy is present
- SMTP smuggling affects Exim 4.83–4.100; the GnuTLS flaw hits 4.98–4.100
- Top CVSS score is 7.5; no public exploits or confirmed attacks reported
- Three of the four flaws have no workaround, so patching is required
Read next
Security