Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43861

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

A flaw was found in mutt, an email client. The url_pct_decode function, which is responsible for decoding URL-encoded strings, does not correctly handle null termination characters. This vulnerability could allow a remote attacker, to manipulate how URLs are processed, potentially leading to a limited loss of data integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10muttOut of support scope
Red Hat Enterprise Linux 6muttOut of support scope
Red Hat Enterprise Linux 7muttFix deferred
Red Hat Enterprise Linux 8muttFix deferred
Red Hat Enterprise Linux 9muttFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2464868mutt: Mutt: URL processing vulnerability due to improper null character handling

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

CVSS3: 3.7
nvd
3 месяца назад

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

CVSS3: 3.7
debian
3 месяца назад

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

CVSS3: 3.7
github
3 месяца назад

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

suse-cvrf
около 2 месяцев назад

Security update for mutt

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3