Heap Buffer Overflow in Hashcat's KeePass AESKDF/KDBX v4 Module
CVE-2026-68765
5.2MEDIUM
What is CVE-2026-68765?
The Hashcat KeePass AESKDF/KDBX v4 module is susceptible to a heap buffer overflow due to insufficient input length checks. Attackers can exploit this by providing an oversized ninth hash field token, which can contain up to 600 hex characters. As the module decodes this input into a fixed 256-byte buffer without validating the length, it allows an overflow that can corrupt adjacent heap memory. This vulnerability raises significant concerns regarding potential memory access violations, as it may lead to unpredictable behavior or execution of arbitrary code.
Affected Version(s)
hashcat ef52453de9523f6a010652847b61cb340ed5daa5
