PT-2026-36774 · Mutt · Mutt

·

CVE-2026-43861

·

Published

2026-05-04

·

Updated

2026-06-22

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions mutt versions prior to 2.3.2
Description The software fails to check for the null character '0' within the url pct decode() function.
Recommendations Update to version 2.3.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85602
CVE-2026-43861
OESA-2026-2200
OPENSUSE-SU-2026:10695-1
OPENSUSE-SU-2026:21016-1
SUSE-SU-2026:22340-1
SUSE-SU-2026:2300-1
SUSE-SU-2026:2301-1

Affected Products

Mutt