CVE-2026-43860

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

low 3.7 CVSS 3.1
Published: May 4, 2026
Modified: May 4, 2026

Description

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

References