Mumble is an open-source voice-communication platform widely used in gaming and collaborative environments, with its vulnerability surface concentrated in a single product line. The recurring weaknesses—input validation, link-following, and out-of-bounds read conditions—reflect the parsing and file-handling challenges inherent to a network audio application. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mumble over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27229HIGH Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. | Feb 16, 2021 | 8.8 | 29 | NO | NO |
CVE-2018-20743HIGH murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of ser | Jan 25, 2019 | 7.5 | 25 | NO | NO |
CVE-2010-2490MEDIUM Mumble: murmur-server has DoS due to malformed client query | Oct 31, 2019 | 6.5 | 23 | NO | NO |
CVE-2025-71264MEDIUM Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash). | Mar 16, 2026 | 5.3 | 20 | NO | NO |
CVE-2020-13962HIGH Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users | Jun 9, 2020 | 7.5 | 20 | NO | NO |
CVE-2014-3756MEDIUM The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a denial of service (hang and resource consumption) via a crafted | Nov 16, 2014 | 5.0 | 15 | NO | NO |
CVE-2014-3755MEDIUM The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of service (hang and resource consumption) via a local file refere | Nov 16, 2014 | 5.0 | 15 | NO | NO |
Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext | Apr 30, 2012 | 2.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mumble.
Media articles that mention a CVE ID that affects a product developed by Mumble — matched by CVE ID, not by vendor name.