CVE-2020-14154: Medium severity Mutt Mutt vulnerability
Last updated 25 August 2025
Other sources
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-14154?
CVE-2020-14154 is a vulnerability in Mutt before version 1.14.3 that allows a connection to proceed even if the user rejects an expired intermediate certificate.
How severe is CVE-2020-14154?
CVE-2020-14154 has a severity rating of 4.8, which is considered medium severity.
Which software is affected by CVE-2020-14154?
CVE-2020-14154 affects Mutt versions before 1.14.3 and neomutt versions before 20220429+dfsg1-4.1.
How can I mitigate the impact of CVE-2020-14154?
To mitigate the impact of CVE-2020-14154, update Mutt to version 1.14.3 or neomutt to version 20220429+dfsg1-4.1.
Where can I find more information about CVE-2020-14154?
You can find more information about CVE-2020-14154 in the Mutt-announce mailing list, the Mutt website, and the Gentoo bug report linked in the references.