Out-of-Bounds Heap Write Vulnerability in hashcat by Hashcat Community
CVE-2026-68767

6.9MEDIUM

Key Information:

Vendor

Hashcat

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-68767?

The fgetl() function in hashcat's file handling module incorrectly writes a null terminator one byte beyond the allocated buffer when the input line matches the buffer size. This can be exploited by attackers supplying specially crafted hash files, potfiles, or wordlists that contain lines precisely HCBUFSIZ_LARGE bytes long, potentially leading to buffer corruption or other unintended behaviors. Immediate action is recommended for users of hashcat versions up to 7.1.2 to address this issue.

Affected Version(s)

hashcat 0 <= 7.1.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Piotr Kowalczyk
.