CVE-2026-56766: Hydra - Stack Buffer Overflow in NTLM Authentication Handler
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hydrato a version that resolves this vulnerability.Fixed in 9.7Patch commit 9cc84c2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56766?
The severity of CVE-2026-56766 is rated as high, with a score of 8.6.
How do I fix CVE-2026-56766?
To fix CVE-2026-56766, upgrade Hydra to version 9.8 or later where the vulnerability has been patched.
What is the impact of CVE-2026-56766?
CVE-2026-56766 may allow a malicious server to exploit a stack buffer overflow, potentially leading to remote code execution.
Which modules of Hydra are affected by CVE-2026-56766?
CVE-2026-56766 affects Hydra's NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules.
Is CVE-2026-56766 a common vulnerability?
CVE-2026-56766 is a specific and notable vulnerability due to its high severity and the widespread use of Hydra for various protocols.