PatchSiren

mutt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW mutt CVE published 2026-10-08

CVE-2026-107570

A low-severity CVE-2026-107570 vulnerability was disclosed in the Mutt email client on October 8, 2026. The issue is a heap out-of-bounds write in the `convert_file_from_to()` function, triggered by a crafted Content-Type header when an email is used as a template. This CVE has a CVSS score of 2.5 and is considered low severity. The vulnerability affects Mutt email client deployments and requires verifica [truncated]