PatchSiren cyber security CVE debrief
CVE-2026-107570 mutt CVE debrief
A low-severity CVE-2026-107570 vulnerability was disclosed in the Mutt email client on October 8, 2026. The issue is a heap out-of-bounds write in the `convert_file_from_to()` function, triggered by a crafted Content-Type header when an email is used as a template. This CVE has a CVSS score of 2.5 and is considered low severity. The vulnerability affects Mutt email client deployments and requires verification of versions and configurations to determine exposure. Defenders should assess email processing and template handling contexts for potential vulnerabilities and monitor for updates from the Mutt vendor. The CVE Program record and NVD vulnerability detail provide official and N
- Vendor
- mutt
- Product
- Unknown
- CVSS
- LOW 2.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for email client security, particularly those using Mutt, should assess exposure and verify versions in use. Additionally, security teams handling email processing and template handling configurations should review their systems for potential vulnerabilities.
Why it matters
CVE-2026-107570 is a low-severity vulnerability in Mutt that requires verification of versions and configurations to determine exposure. Defenders should assess email processing and template handling contexts for potential vulnerabilities and monitor for updates from the Mutt vendor.
- Verification of Mutt versions and configurations is necessary to determine exposure.
- Email processing and template handling configurations may be vulnerable to exploitation.
- Remediation or mitigation strategies from the Mutt vendor should be monitored and implemented as necessary.
- Further investigation is required to fully understand the vulnerability's impact and potential consequences.
Technical summary
The CVE-2026-107570 vulnerability is a heap out-of-bounds write in the `convert_file_from_to()` function of the Mutt email client. This issue is triggered by a crafted Content-Type header when an email is used as a template, potentially allowing an attacker to perform an out-of-bounds write.
Defensive priority
Defenders should prioritize verification of Mutt versions and assess exposure, especially in email processing and template handling contexts.
Recommended defensive actions
- Verify Mutt versions in use and assess exposure to CVE-2026-107570
- Review email processing and template handling configurations for potential vulnerabilities
- Monitor for updates from the Mutt vendor regarding remediation or mitigation strategies
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. A source reference from GitLab is also available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107570 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107570
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107570 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107570
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Use of Out-of-range Pointer Offset in mutt
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107570.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/muttmua/mutt/-/work_items/533
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.