FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mutt -- Heap out-of-bounds write via crafted Content-Header line

Affected packages
mutt < 2.4.3

Details

VuXML ID 28c48cd9-e79a-4ad6-8e62-1317c2ec19a1
Discovery 2026-10-08
Entry 2026-10-09

Kevin J. McCarthy reports:

Fixing an OOB heap write. This is triggered by a specially crafted Content-Header line in an email that is used as a template for a new email, via <resend-message >. Thanks to Calif.io, in collaboration with Anthropic for sending me a detailed write up and suggested patch.

References

CVE Name CVE-2026-107570
URL https://www.cve.org/CVERecord?id=CVE-2026-107570