There are 6 open security issues in bookworm.
6 issues left for the package maintainer to handle:
- CVE-2026-43859:
(needs triaging)
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-43860:
(needs triaging)
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
- CVE-2026-43861:
(needs triaging)
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43862:
(needs triaging)
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
- CVE-2026-43863:
(needs triaging)
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2026-43864:
(needs triaging)
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
You can find information about how to handle these issues in the security team's documentation.