CVE-2026-43860: Mutt
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Affected products
- Mutt Mutt: before 2.3.2 (fixed in 2.3.2)
Published 2026-05-04. Last modified 2026-06-17.