Title: Exim Security Advisory for EXIM-Security-2026-06-22.1 / GCVE-25-2026-07-45-1
Announced: 2026-07-22
Affects: Exim 4.88 up to and including 4.99.4
Corrected: Exim 4.99.5

Exim Security Vulnerability: EXIM-Security-2026-06-22.1
=========================================================

Identifier:   EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1)
Type:         Directory traversal, local
Severity:     High
Credit:       The unnamed and uncredited authors whose works
	      were ingested as the training corpus

Timeline
--------

  2026-06-22 20:11 UTC Report received
  2026-06-23 11:57 UTC Fix drafted
  2026-07-12 12:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/)
  2026-07-13 19:25 UTC Advance notice sent to distros@vs.openwall.org
  2026-07-15 11:05 UTC Fix branch and tag exim-4.99.5 pushed to exim-distros
  2025-07-22 14:00 UTC Public release

Vulnerability Summary
---------------------

Using command-line arguments intended for transferring queue-name through
an Exim execution chain, files outside the spool area can be accessed.
This can be used for a privilege escalation.

Affected Versions
-----------------

- Exim versions from 4.88 (2017) up to and including 4.99.4 are affected.
  The development version (master) was affected as well.
- To reach the vulnerable code, the attacker needs command-line access
  on the system.

Mitigation
----------

(None)

Resolution
----------

The issue is resolved in Exim version 4.99.5. All users of affected
versions are strongly encouraged to upgrade.

The fix restricts the use of relevant command-line options to already-
privileged users, and restricts the characters that may be used for
queue names.

Downloads
---------

The new version is available from the usual locations:

- https://ftp.exim.org/pub/exim/exim4/
- https://code.exim.org/exim/exim (branch exim-4.99+fixes, tag exim-4.99.5)

The release tag exim-4.99.5, signed by Jeremy Harris <jgh146exb@wizmail.org>,
key A986F3A6BD6377D8730958DEBCE58C8CE41F32DF
