{"id":"CVE-2026-68768","summary":"hashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized Username","details":"hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process.","modified":"2026-08-27T18:53:48.773182Z","published":"2026-08-22T14:12:44.241Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68768.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68768.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68768"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hashcat-through-heap-buffer-overflow-in-outfile-write-via-oversized-username"},{"type":"REPORT","url":"https://github.com/hashcat/hashcat/issues/4740"},{"type":"FIX","url":"https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89"},{"type":"PACKAGE","url":"https://github.com/hashcat/hashcat"},{"type":"ARTICLE","url":"https://github.com/hashcat/hashcat/blob/v7.1.2/src/outfile.c#L654-L668"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashcat/hashcat","events":[{"introduced":"0"},{"fixed":"68f56a2d8712867a8520bf4dcf07f6145c23df89"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"7.1.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v7.1.2","v7.1.1","v7.1.0","v7.0.0","v6.2.6","v6.2.5","v6.2.4","v6.2.3","v6.1.1","v6.2.2","v6.2.1","v6.2.0","v6.1.0","v6.0.0","v5.1.0","v5.0.0","v4.2.1","v4.2.0","v4.1.0","v4.0.1","v4.0.0","v3.6.0","v3.5.0","v3.40","v3.30","v3.20","v3.10","v3.00","v3.00-beta","v2.01","v2.00"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68768.json","vanir_signatures_modified":"2026-08-27T18:53:48Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["313335503426377106090268755464626508698","12742215621192691250584981362337859000","299234216698683046207859638933331435117","284876255893746927784938932065818713269","317229801615926824937900669823212647914","152986387284065430859431034986529658535","119512505878697528163707405288514650234","189225464707760294551926348737817591470","130170598854145021994829550568999913453","334704934364903297938012458668345463136","68175488793439826487970812301766186939","169284945694981615956800681834349093470","70426860223430066682741711042566652676","65461471712681411685271880336012798762","116006569035726899927355624793994509711","2113651800602651956041768482859261145","129806993635521334888823439408201170362","319339964665869106053178659874760441187","58549679794047619363437989055850159327","112236749633582678870033091571156926529","335484187190174437647080745686211102766","58829834533378132245428962396663070820","106851454116321511284895512611075324671","3293949169513003997662465315713845535","169087480098320201913164244005763158468","68746860955911568716644541957483755706","127462346305946171116633772773648784099","319339964665869106053178659874760441187","246800938876291297516386490095506734270","230399809820598876324449826289463463729","175843094398447282036526131252161157187","134063484676373840866186295721345947035","98874145643366978529879920869125199261","124382503301801161224146595828326445390","68417542028473743323944392724136091493","92652692528522107853129265246444490839","319339964665869106053178659874760441187","254945646026305467865800046737543171034","160214923473978817133575570005031335913","5773844855711297759333953835259849877","322453676218076115239243944090264962860","80935655199155162279788538810451580152","276088578795903271793502279151356394190","79794249823921247874804975534737048500","231621697838895436132110189028266210948","112811303467833229263467046037265247342","178766911642029076750263393554487121086","205983696816111262978398475670261526574","212793579414798121822245124492095046350","299332273309730173979880784404869681806","293364410916315118780056452541028256294","218366919077585473727669879028614389617","320689703326859975672733292589499428344","110327225990346220220925568153115771175","241102667661275917904636815239603762360","340196544790968627684123068448688899579","99816928716084688580572431476170396825","209682642033224233445428755995095303458","312834220087245989295372689103005235718","33552505735980830468113039133088264932","129377739029630731885396245820728862391","39283444780173825381839824328793123289","189003045172528461571147376886606028080","340196544790968627684123068448688899579","99816928716084688580572431476170396825","242178009287942812815458323362239419900","131184154849930378981105239058086874","304631446084995448970667324085994353993","173442012568963848564807266602311629276","203929639632453278243923569278932965149","119685218172237800429904477013030386299","340196544790968627684123068448688899579","99816928716084688580572431476170396825","114798602500290955128688917713875430019","302095333568928659149626284198176667340","223315126858290737745675599881919689050","8664768284055057745328038994750700039","68185933921917420670385607442539736546","337919101005957996726161911714673350634","37345821249250112577046317154303464769","185183779173079808098841820120160327816","340196544790968627684123068448688899579","99816928716084688580572431476170396825","266479566912850800713331608275033041512","31819343202119523340360608240131078539","278108767529089108092088117722221225860","113673395877896228175263237259104123674","242960868688578593362819091667770314312","310370713775510615569685670277933809099","83270817968387512638401993773909846452","235091033839092715776030356022844640207","145460763743176661853937291686933873824","111038293656509985263572486149636790463","189028882941040789336770891286706736890","128465380724883205630404483688222240939","12110857864730605133281633365145848866","168382984931505812867543529714408788931","13656726223753546190192731058399479388","75740969152510277763503058706480567258","54631742291768748979751069751726850304","301124191465356362776650699237994929955","318631001629090398793517580947849407084","340196544790968627684123068448688899579","99816928716084688580572431476170396825","296191121889894263712229845886342353605","140846324464264314752145689714295936794","88979525820313667719997982113500002647","273766154098359575337129584811278008599","181401032979144145836029616443555376978","196694492344239343185737745297416345229","321947177461728996681833372041466592136","173250410862659730429355591927142245397","340196544790968627684123068448688899579","99816928716084688580572431476170396825","233841335227126610782071624564050890664","83858593865242950021160193978863385037","54145219035886231724847250253614278285","40528637602994925461974410066202709742","106048251640499228490440884994854900958","278828268700867573739234752217229511912"],"threshold":0.9},"id":"CVE-2026-68768-a44fbc5c","signature_type":"Line","signature_version":"v1","source":"https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89","target":{"file":"src/outfile.c"}},{"target":{"file":"src/outfile.c","function":"outfile_write"},"deprecated":false,"digest":{"function_hash":"275781386081354921069555504340660439682","length":4328},"id":"CVE-2026-68768-de6026df","signature_type":"Function","signature_version":"v1","source":"https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}]}