Mintty is a lightweight terminal emulator for Windows and Cygwin environments with a narrow product scope but notable presence in Unix-on-Windows development workflows. Its vulnerability history centers on resource management and output-handling issues, including unthrottled allocation, buffer overflows, and injection-class flaws characteristic of systems that parse and render untrusted terminal sequences. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mintty Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1052HIGH Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Feb 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-39726CRITICAL An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal. | Oct 26, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-47583CRITICAL Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. | Oct 19, 2023 | 9.8 | 25 | NO | NO |
CVE-2021-28848HIGH Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results i | Jun 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-31701HIGH Mintty before 3.4.7 mishandles Bracketed Paste Mode. | Jun 6, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mintty Project.
Media articles that mention a CVE ID that affects a product developed by Mintty Project — matched by CVE ID, not by vendor name.