Back to VulnFeed / CVE-2026-43860
root@hackertop:~/vulnfeed/CVE-2026-43860#
CVE-2026-43860 MEDIUM CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

mutt up to 2.3.1 IMAP hash_passwd off-by-one

mutt 17d ago Impact pending confirmation
LIFECYCLE
4.3 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in mutt up to 2.3.1 (Mail Client Software) and classified as problematic. Affected by this issue is the function hash_passwd of the component IMAP. Upgrading to version 2.3.2 eliminates this vulnerability.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-193. A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Impact: Impacted is confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 2.3.2 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-43860 · CVSS 4.3 · Active Threat