Heap Out-of-Bounds Write Vulnerability in Mutt Email Client
CVE-2026-107570

2.5LOW

Key Information:

Vendor

Mutt

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107570?

A vulnerability in the Mutt email client allows for heap out-of-bounds writes via a crafted Content-Type header within email templates. This exposure can potentially enable unauthorized alterations or access to sensitive data, highlighting the need for robust security measures and prompt updates to mitigate associated risks.

Affected Version(s)

mutt 0 <= 2.4.2

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Calif.io, in collaboration with Anthropic
.