CVE-2019-10149: Exim Mail Transfer Agent (MTA) Improper Input Validation
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-01-10. EPSS: 100% chance of exploitation in the next 30 days.
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Debian Debian Linux: version 9.0 only
- Exim Exim: from 4.87, up to and including 4.91
Published 2019-06-05. Last modified 2026-06-17.