Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-56766: Hydra 9.7 and earlier: Stack Buffer Overflow in NTLM Authentication
CVE-2026-56766
CVE-2026-56766
Summary
Hydra, a password cracking tool, has a security flaw that could allow hackers to take control of a system. This flaw affects various email and web services like SMTP, POP3, IMAP, NNTP, HTTP, and others. To stay safe, update Hydra to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vanhauser-thc | thc-hydra | <= 9.7 |
Original title
Hydra - Stack Buffer Overflow in NTLM Authentication Handler
Original description
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.6
Vulnerability type
CWE-121
Stack-based Buffer Overflow
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026