Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
https://www.openwall.com/lists/oss-security/2025/12/11/2
https://exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt
https://exim.org/static/doc/security/