
CVE-2026-43860 mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest. https://www.cve.org/CVERecord?id=CVE-2026-43860
Post summary
The statement discloses a specific flaw in mutt versions prior to 2.3.2 that incorrectly truncates the IMAP auth_cram MD5 digest by one byte.

