PT-2026-52540 · Hydra · Hydra

·

CVE-2026-56766

·

Published

2026-06-25

·

Updated

2026-06-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hydra versions prior to 9.7 commit 9cc84c2
Description A stack buffer overflow exists in the NTLM authentication process across the SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules. The issue occurs when the software processes a malicious NTLM Type-2 challenge—a response from a server during the NTLM authentication handshake. A malicious server can send a crafted challenge containing an excessively long domain string, causing the base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes. This can enable remote code execution on systems that lack stack protection.
Recommendations Update Hydra to the version containing commit 9cc84c2.

Exploit

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56766
OPENSUSE-SU-2026:11131-1

Affected Products

Hydra