{"id":"CVE-2026-56766","summary":"Hydra - Stack Buffer Overflow in NTLM Authentication Handler","details":"Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.","modified":"2026-06-26T04:11:21.338352808Z","published":"2026-06-25T18:01:07.362Z","database_specific":{"cwe_ids":["CWE-121"],"cna_assigner":"VulnCheck","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56766.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56766.json"},{"type":"PACKAGE","url":"https://github.com/vanhauser-thc/thc-hydra"},{"type":"FIX","url":"https://github.com/vanhauser-thc/thc-hydra/commit/9cc84c20e75f5fef6bb1790bb9ada2afad2204e2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56766"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hydra-stack-buffer-overflow-in-ntlm-authentication-handler"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vanhauser-thc/thc-hydra","events":[{"introduced":"0"},{"last_affected":"6c11ce2dff19ce81630c12b001d821dcd4d1567c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"9.7"}],"source":"AFFECTED_FIELD"}}],"versions":["v9.7","v9.6","v9.5","v9.4","v9.3","v9.2","v9.1","v8.8","v9.0","v8.9.1","8.6","v8.5","v8.4","8.3","v8.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-56766.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}