vulnerability in mutt email client impacting authentication method
CVE-2026-43859
3.7LOW
What is CVE-2026-43859?
The Mutt email client prior to version 2.3.2 has a vulnerability where it incorrectly utilizes strfcpy in place of memcpy during the IMAP auth_cram MD5 digest process. This flaw could potentially compromise the integrity of authentication and may expose sensitive user data. It’s important for users to update to the latest version to mitigate this risk.
Affected Version(s)
mutt 0 < 2.3.2
