Description
heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template.
Published: 2026-10-08
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds heap write when an email is used as a template
Action: Apply patch
AI Analysis

Impact

Heap out‑of‑bounds write vulnerabilities arise in the mutt mail user agent’s convert_file_from_to() routine. By sending a message with a specially crafted Content‑Type header, an attacker can trigger an out‑of‑range pointer offset and overwrite adjacent heap memory. This flaw could corrupt program data, cause crashes, or create a vehicle for arbitrary code execution, depending on the exact memory layout and context. The weakness is classified as CWE‑787.

Affected Systems

The flaw exists in all mutt releases older than 2.4.3. Users running mutt from earlier releases, whether on Linux, macOS, or other platforms, are susceptible unless they have applied the official patch that is included in version 2.4.3 and later.

Risk and Exploitability

The CVSS score of 2.5 places the issue in the low severity range, and the EPSS score is currently unavailable, suggesting no publicly observed exploitation yet. The vulnerability is also not listed in the CISA KEV catalog. Given the requirement of a crafted email header to trigger the OOB write, the theoretical attack vector is an email that the client processes as a template. Although the low CVSS and lack of exploitation evidence reduce immediate risk, the potential for arbitrary memory corruption warrants timely remediation.

Generated by OpenCVE AI on October 9, 2026 at 03:16 UTC.

Remediation

Vendor Solution

Upgrade to 2.4.3


OpenCVE Recommended Actions

  • Install mutt 2.4.3 or a later version from an official source to replace the vulnerable routine.
  • Verify the integrity of the newly installed package by comparing published checksums or digital signatures with the downloaded binary.
  • Monitor mutt patches or updates, and apply them promptly to maintain protection.

Generated by OpenCVE AI on October 9, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
References

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Low


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Mutt
Mutt mutt
Vendors & Products Mutt
Mutt mutt

Thu, 08 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template.
Title Use of Out-of-range Pointer Offset in mutt
Weaknesses CWE-823
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-09T23:07:33.453Z

Reserved: 2026-10-08T10:51:15.640Z

Link: CVE-2026-107570

cve-icon Vulnrichment

Updated: 2026-10-09T23:07:33.453Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:14.717

Modified: 2026-10-10T00:17:03.540

Link: CVE-2026-107570

cve-icon Redhat

Severity : Low

Publid Date: 2026-10-08T11:33:26Z

Links: CVE-2026-107570 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T03:30:06Z

Weaknesses
  • CWE-787

    Out-of-bounds Write

  • CWE-823

    Use of Out-of-range Pointer Offset