CVE-2026-43863: Mutt

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

Affected products

  • Mutt Mutt: before 2.3.2 (fixed in 2.3.2)

Published 2026-05-04. Last modified 2026-06-17.