PT-2026-96115 · Fetchmail · Fetchmail

CVE-2026-94184

·

Published

2026-09-21

·

Updated

2026-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions fetchmail versions 5.0.8 through 6.6.6
Description A stack-based buffer overflow occurs in fetchmail when it is compiled with NTLM support. A malicious or compromised mail server that advertises NTLM authentication can send a specially crafted Type 2 challenge. This causes the application to write data beyond a fixed stack buffer during the construction of the NTLM authentication response. Depending on the stack-frame layout, this can result in remote code execution, authentication failure, or process termination due to memory hardening.
Recommendations Update fetchmail versions 5.0.8 through 6.6.6 to a version where this issue is resolved. As a temporary mitigation, avoid using NTLM authentication when fetching mail from untrusted servers.

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94184

Affected Products

Fetchmail