CVE-2026-94184: Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)

Published Sep 21, 2026
·
Updated

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.

Affected Software

1 affected component
fetchmail

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade fetchmail to a version that resolves this vulnerability.

    Patch fetchmail-sa-2026-01

Event History

Sep 21, 2026
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Fetchmail deployments built with NTLM support are exposed when they connect to a mail server that advertises NTLM authentication. A malicious or compromised server can trigger the flaw remotely.

2

Does exploitation require credentials, user interaction, or a local foothold?

No privileges or user interaction are required according to the supplied vector. The attacker needs to control, or compromise, a mail server encountered by the affected fetchmail client and provide a crafted NTLM Type 2 challenge.

3

What can happen if the flaw is triggered?

The crafted challenge can cause a write past a fixed stack buffer while fetchmail builds its NTLM authenticate response. Depending on stack-frame layout and memory hardening, the result may be remote code execution, authentication failure, or fetchmail process termination.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203