CVE-2020-14954: Medium severity Mutt Mutt vulnerability
Last updated 25 August 2025
Other sources
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14954.
What is the severity of CVE-2020-14954?
The severity of CVE-2020-14954 is medium, with a severity value of 5.9.
Which software versions are affected by CVE-2020-14954?
Mutt before 1.14.4 and NeoMutt before 2020-06-19 are affected by CVE-2020-14954.
What is the remedy for CVE-2020-14954?
The remedy for CVE-2020-14954 is to update to the patched versions: Mutt 1.14.4 or later, and NeoMutt 2020-06-19 or later.
Where can I find more information about CVE-2020-14954?
More information about CVE-2020-14954 can be found at the following references: [http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200615/000023.html](http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200615/000023.html), [http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00064.html](http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00064.html), [http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00070.html](http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00070.html)