Back to VulnFeed / CVE-2026-43861
root@hackertop:~/vulnfeed/CVE-2026-43861#
CVE-2026-43861 MEDIUM CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

mutt up to 2.3.1 url_pct_decode null byte or nul character

mutt 17d ago Impact pending confirmation
LIFECYCLE
4.3 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability classified as problematic has been found in mutt up to 2.3.1 (Mail Client Software). This affects the function url_pct_decode. Upgrading to version 2.3.2 eliminates this vulnerability.
Root Cause Analysis
CWE is classifying the issue as CWE-158. The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.

Impact: This is going to have an impact on confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 2.3.2 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-43861 · CVSS 4.3 · Active Threat