In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
CVE ID: CVE-2024-49395
Vendor: , Red Hat
Product: , Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 14.04% (scored less or equal to compared to others)
EPSS Date: 2025-07-13 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: true