CVE-2026-43860: Low severity Mutt Mutt vulnerability
Published May 4, 2026
·Updated
mutt before 2.3.2 sometimes truncates the hashpasswd by one byte for IMAP authcram MD5 digest.
Affected Software
1 affected component
Mutt Mutt<2.3.2
Event History
May 4, 2026
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-43860?
CVE-2026-43860 is considered a medium severity vulnerability due to potential authentication bypass in Mutt.
2
How do I fix CVE-2026-43860?
Upgrade Mutt to version 2.3.2 or later to resolve CVE-2026-43860.
3
What versions of Mutt are affected by CVE-2026-43860?
Mutt versions prior to 2.3.2 are affected by CVE-2026-43860.
4
What type of vulnerability is CVE-2026-43860?
CVE-2026-43860 is an authentication-related vulnerability affecting IMAP auth_cram MD5 digest.
5
Does CVE-2026-43860 require immediate action?
Yes, it is recommended to address CVE-2026-43860 promptly to prevent potential security risks.