In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
{
"priority_reason": "This is a longstanding limitation of PGP-encrypted mail and is an enhancement rather than an actual vulnerability.",
"binaries": [
{
"binary_name": "mutt",
"binary_version": "1.5.24-1ubuntu0.6+esm3"
},
{
"binary_name": "mutt-patched",
"binary_version": "1.5.24-1ubuntu0.6+esm3"
}
]
}