CVE detail
CVE-2020-28896 — CVE-2020-28896
Published 2020-11-23 · Modified 2026-06-17 · Vendor mutt · Product mutt · Source nvd
MEDIUM
severity
CVSS-derived band
0.0232
EPSS probability
exploitation probability, 30d
82.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References