Mutt Denial-of-Service Vulnerability Due to Infinite Loop in GPGME Data Handling

Vulnerability

A denial-of-service vulnerability has been identified in Mutt versions prior to 2.3.2. The issue arises from an infinite loop in the function 'data_object_to_stream' within 'crypt-gpgme.c'. This loop occurs because the code does not properly handle a specific return value, leading to excessive processing and potentially causing the application to hang.

Impact

Exploitation of this vulnerability leads to an infinite loop, causing the application to become unresponsive.

Remediation

Users can upgrade to Mutt version 2.3.2 or later to address this vulnerability.

Added: May 4, 2026, 7:30 AM
Updated: May 4, 2026, 7:30 AM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
0.6
exploitability
4.9
remediation
7.7
relevance
7.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.