---
id: CVE-2026-94057
title: >-
  Exim before 4.100.1 allows SMTP smuggling in which the received message does
  not match any sent message, and instead depends on crafted data sent after a
  rejection during DATA processing.
summary: >-
  Exim before 4.100.1 allows SMTP smuggling in which the received message does
  not match any sent message, and instead depends on crafted data sent after a
  rejection during DATA processing.
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-93
vendor: Exim
product: Exim
affected:
  - Exim < 4.100.1
published: '2026-09-19'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T23:17:11.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94057'
references:
  - url: 'https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-19T23:10:34.246Z'
epss: 0.00162
epssPercentile: 0.05863
---

## Overview

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
