Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-56766: Hydra 9.7 and earlier: Stack Buffer Overflow in NTLM Authentication

CVE-2026-56766 CVE-2026-56766
Summary

Hydra, a password cracking tool, has a security flaw that could allow hackers to take control of a system. This flaw affects various email and web services like SMTP, POP3, IMAP, NNTP, HTTP, and others. To stay safe, update Hydra to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
vanhauser-thc thc-hydra <= 9.7
Original title
Hydra - Stack Buffer Overflow in NTLM Authentication Handler
Original description
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.
nvd CVSS3.1 8.8
nvd CVSS4.0 8.6
Vulnerability type
CWE-121 Stack-based Buffer Overflow
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026