CVE-2025-71264: Medium severity Mumble Mumble vulnerability
Published Mar 16, 2026
·Updated
Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
Affected Software
2 affected components
Mumble Mumble<1.6.870
Mumble Mumble<1.6.870
Remediation
Patch Available
Event History
Mar 16, 2026
CVE Published
via MITRE·06:13 AM
Data Sourced
via MITRE·06:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71264?
CVE-2025-71264 is classified as a denial of service vulnerability due to an out-of-bounds array access.
2
How do I fix CVE-2025-71264?
To fix CVE-2025-71264, upgrade to Mumble version 1.6.870 or later.
3
What versions of Mumble are affected by CVE-2025-71264?
CVE-2025-71264 affects Mumble versions prior to 1.6.870.
4
What can happen if I am using an affected version of Mumble related to CVE-2025-71264?
Using an affected version of Mumble may result in client crashes or denial of service.
5
Is there a workaround for CVE-2025-71264 if I cannot immediately upgrade?
There are no known workarounds for CVE-2025-71264, and upgrading is the recommended response.