CVE-2026-43863: Low severity Mutt Mutt vulnerability
Published May 4, 2026
·Updated
mutt before 2.3.2 has an infinite loop in dataobjecttostream in crypt-gpgme.c.
Affected Software
1 affected component
Mutt Mutt<2.3.2
Event History
May 4, 2026
CVE Published
via MITRE·06:05 AM
Data Sourced
via MITRE·06:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-43863?
The severity of CVE-2026-43863 is classified as medium due to the potential for denial of service from an infinite loop.
2
How do I fix CVE-2026-43863?
To fix CVE-2026-43863, upgrade to Mutt version 2.3.2 or later.
3
What versions of Mutt are affected by CVE-2026-43863?
Mutt versions prior to 2.3.2 are affected by CVE-2026-43863.
4
Can CVE-2026-43863 be exploited remotely?
CVE-2026-43863 can potentially be exploited remotely if an attacker can manipulate messages processed by the affected Mutt versions.
5
What component of Mutt is vulnerable in CVE-2026-43863?
CVE-2026-43863 involves an infinite loop in the data_object_to_stream function within crypt-gpgme.c.