Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim
xbow.com | vulnerability | Critical | CVE-2026-45185 | #rce | #vulnerability-research | #use-after-free | #exim | #cve-2026-45185 | #gnutls
Summary
XBOW recounts finding CVE-2026-45185, an unauthenticated Exim RCE: during GnuTLS TLS shutdown, a nested BDAT wrapper's ungetc() writes one byte into freed memory, corrupting allocator metadata.
- CVSS
- 9.8
- Published
- Collected
Skip to content