Title: Exim Security Advisory for EXIM-Security-2026-06-22.1 / GCVE-25-2026-07-45-1 Announced: 2026-07-22 Affects: Exim 4.88 up to and including 4.99.4 Corrected: Exim 4.99.5 Exim Security Vulnerability: EXIM-Security-2026-06-22.1 ========================================================= Identifier: EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1) Type: Directory traversal, local Severity: High Credit: The unnamed and uncredited authors whose works were ingested as the training corpus Timeline -------- 2026-06-22 20:11 UTC Report received 2026-06-23 11:57 UTC Fix drafted 2026-07-12 12:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/) 2026-07-13 19:25 UTC Advance notice sent to distros@vs.openwall.org 2026-07-15 11:05 UTC Fix branch and tag exim-4.99.5 pushed to exim-distros 2025-07-22 14:00 UTC Public release Vulnerability Summary --------------------- Using command-line arguments intended for transferring queue-name through an Exim execution chain, files outside the spool area can be accessed. This can be used for a privilege escalation. Affected Versions ----------------- - Exim versions from 4.88 (2017) up to and including 4.99.4 are affected. The development version (master) was affected as well. - To reach the vulnerable code, the attacker needs command-line access on the system. Mitigation ---------- (None) Resolution ---------- The issue is resolved in Exim version 4.99.5. All users of affected versions are strongly encouraged to upgrade. The fix restricts the use of relevant command-line options to already- privileged users, and restricts the characters that may be used for queue names. Downloads --------- The new version is available from the usual locations: - https://ftp.exim.org/pub/exim/exim4/ - https://code.exim.org/exim/exim (branch exim-4.99+fixes, tag exim-4.99.5) The release tag exim-4.99.5, signed by Jeremy Harris , key A986F3A6BD6377D8730958DEBCE58C8CE41F32DF