CVE-2026-43859

EUVD-2026-26895
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.89%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
muttmutt
𝑥
< 2.3.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
mutt
bookworm
no-dsa
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
2.4.1-1
fixed
sid
2.4.1-1
fixed
trixie
2.2.13-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mutt
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
mutt
suse enterprise desktop 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise sap 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise server 15 SP4
1.10.1-150000.3.29.1
fixed
suse enterprise server 15 SP7
2.2.14-150600.3.6.1
fixed
mutt-doc
suse enterprise desktop 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise sap 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise server 15 SP4
1.10.1-150000.3.29.1
fixed
suse enterprise server 15 SP7
2.2.14-150600.3.6.1
fixed
mutt-lang
suse enterprise desktop 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise sap 15 SP7
2.2.14-150600.3.6.1
fixed
suse enterprise server 15 SP4
1.10.1-150000.3.29.1
fixed
suse enterprise server 15 SP7
2.2.14-150600.3.6.1
fixed