CVE-2025-61962: Fetchmail

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.

Affected products

  • Fetchmail Fetchmail: from 5.9.9, before 6.5.6 (fixed in 6.5.6)

Published 2025-10-04. Last modified 2026-06-17.