PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107570 mutt CVE debrief

A low-severity CVE-2026-107570 vulnerability was disclosed in the Mutt email client on October 8, 2026. The issue is a heap out-of-bounds write in the `convert_file_from_to()` function, triggered by a crafted Content-Type header when an email is used as a template. This CVE has a CVSS score of 2.5 and is considered low severity. The vulnerability affects Mutt email client deployments and requires verification of versions and configurations to determine exposure. Defenders should assess email processing and template handling contexts for potential vulnerabilities and monitor for updates from the Mutt vendor. The CVE Program record and NVD vulnerability detail provide official and N

Vendor
mutt
Product
Unknown
CVSS
LOW 2.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for email client security, particularly those using Mutt, should assess exposure and verify versions in use. Additionally, security teams handling email processing and template handling configurations should review their systems for potential vulnerabilities.

Why it matters

CVE-2026-107570 is a low-severity vulnerability in Mutt that requires verification of versions and configurations to determine exposure. Defenders should assess email processing and template handling contexts for potential vulnerabilities and monitor for updates from the Mutt vendor.

  • Verification of Mutt versions and configurations is necessary to determine exposure.
  • Email processing and template handling configurations may be vulnerable to exploitation.
  • Remediation or mitigation strategies from the Mutt vendor should be monitored and implemented as necessary.
  • Further investigation is required to fully understand the vulnerability's impact and potential consequences.

Technical summary

The CVE-2026-107570 vulnerability is a heap out-of-bounds write in the `convert_file_from_to()` function of the Mutt email client. This issue is triggered by a crafted Content-Type header when an email is used as a template, potentially allowing an attacker to perform an out-of-bounds write.

Defensive priority

Defenders should prioritize verification of Mutt versions and assess exposure, especially in email processing and template handling contexts.

Recommended defensive actions

  • Verify Mutt versions in use and assess exposure to CVE-2026-107570
  • Review email processing and template handling configurations for potential vulnerabilities
  • Monitor for updates from the Mutt vendor regarding remediation or mitigation strategies

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. A source reference from GitLab is also available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107570 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107570

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107570 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107570

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Use of Out-of-range Pointer Offset in mutt

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107570.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.com/muttmua/mutt/-/work_items/533

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.