CVE-2026-11623

NameCVE-2026-11623
DescriptionA security vulnerability has been detected in tmux up to 3.6a. Affecte ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tmux (PTS)bullseye3.1c-1+deb11u1vulnerable
bookworm3.3a-3vulnerable
trixie3.5a-3vulnerable
forky, sid3.6b-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tmuxsource(unstable)(unfixed)

Notes

https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03 (3.7-rc)

Search for package or bug name: Reporting problems