VYPR

Hashcat

by Hashcat

Source repositories

CVEs (7)

  • CVE-2026-42484CriMay 1, 2026
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When…

  • CVE-2026-42483CriMay 1, 2026
    risk 0.64cvss 9.8epss 0.00

    A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted Kerberos hash file. The issue affects module_hash_decode in multiple Kerberos-related modules because…

  • CVE-2026-42482CriMay 1, 2026
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or -k rule options used with password…

  • CVE-2026-68766HigAug 22, 2026
    risk 0.44cvss 7.8epss 0.00

    hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary…

  • CVE-2026-68768MedAug 22, 2026
    risk 0.33cvss 6.1epss 0.00

    hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via…

  • CVE-2026-68767MedAug 22, 2026
    risk 0.33cvss 6.1epss 0.00

    hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of…

  • CVE-2026-68765MedAug 17, 2026
    risk 0.33cvss 6.1epss 0.00

    hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex…