CVE-2026-43861: Low severity Mutt Mutt vulnerability
Published May 4, 2026
·Updated
mutt before 2.3.2 does not check for '\0' in urlpctdecode.
Affected Software
1 affected component
Mutt Mutt<2.3.2
Event History
May 4, 2026
CVE Published
via MITRE·05:52 AM
Data Sourced
via MITRE·05:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-43861?
CVE-2026-43861 is classified as a medium severity vulnerability.
2
How do I fix CVE-2026-43861?
To fix CVE-2026-43861, upgrade Mutt to version 2.3.2 or later.
3
What does CVE-2026-43861 affect?
CVE-2026-43861 affects all versions of Mutt prior to 2.3.2.
4
What type of vulnerability is CVE-2026-43861?
CVE-2026-43861 is a security vulnerability related to improper handling of URL encoding.
5
Can CVE-2026-43861 be exploited remotely?
Yes, CVE-2026-43861 can potentially be exploited remotely if the vulnerable software is exposed.