{"id":"CVE-2026-94184","summary":"Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)","details":"A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.\n\nAffects v5.0.8 through v6.6.6.","modified":"2026-09-24T03:47:49.328623469Z","published":"2026-09-21T14:17:16.053Z","database_specific":{"cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94184.json","cna_assigner":"redhat"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/23/1"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://www.fetchmail.info/fetchmail-SA-2026-01.txt"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/27/8"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-94184"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94184.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94184"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537395"},{"type":"FIX","url":"https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/fetchmail/fetchmail","events":[{"introduced":"2577a80a8110ec4366efdd399d80777e325c0c84"},{"fixed":"9c0580c49c3047efe9906dbe2a7d7017fd6b3829"},{"fixed":"cb5be5c38471eec19e519ace0bc569176317ea92"}],"database_specific":{"extracted_events":[{"introduced":"v5.0.8"},{"fixed":"v6.6.6"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["6.6.6","6.6.5","6.6.4","6.6.3","6.6.2","6.6.1","6.6.0","6.6.0.rc3","6.6.0.rc2","6.6.0.rc1","6.5.7.rc1","6.5.6","6.5.5","6.5.5.rc1","6.5.4","6.5.3","6.5.2","6.5.1","6.5.1.rc1","6.5.0","6.5.0.rc2","6.5.0.rc1","6.5.0.beta10","6.5.0.beta9","6.5.0.beta8","6.5.0.beta7","SNAPSHOT_6-5-0-beta6","6.5.0.beta6","SNAPSHOT_6-5-0-beta5","6.5.0.beta5","SNAPSHOT_6-5-0-beta4","6.5.0.beta4","SNAPSHOT_6-5-0-beta3","6.5.0.beta3","badmerge","SNAPSHOT-6-5-0-beta2","6.5.0.beta2","SNAPSHOT_6-5-0-beta1","6.5.0.beta1","6.5.0.dev20200711b","6.5.0.dev20200711a","SNAPSHOT-6_4_0_rc3","SNAPSHOT-6_4_0_rc2","SNAPSHOT-6_4_0_rc1","SNAPSHOT-6_4_0_beta5","SNAPSHOT-6_4_0_beta4","SNAPSHOT-6_4_0_beta3","SNAPSHOT-6_4_0_beta2","RELEASE_6-3-26","RELEASE_6-3-25","RELEASE_6-3-24","RELEASE_6-3-23","RELEASE_6-3-22","RELEASE_6-3-21","RELEASE_6-3-20","SNAPSHOT_6-3-20-rc3","SNAPSHOT_6-3-20-rc2","SNAPSHOT_6-3-20-pre1","RELEASE_6-3-19","SNAPSHOT_6-3-19-pre1","RELEASE_6-3-18","SNAPSHOT_6-3-18-pre2","SNAPSHOT_6-3-18-pre1","RELEASE_6-3-17","SNAPSHOT_6-3-17-pre1","RELEASE_6-3-16","RELEASE_6-3-15","SNAPSHOT_6-3-15-beta3","SNAPSHOT_6-3-15-beta2","SNAPSHOT_6-3-15-beta1","RELEASE_6-3-8","BRANCH_6-3","RELEASE_6-3-14","RELEASE_6-3-13","RELEASE_6-3-12","RELEASE_6-3-11","RELEASE_6-3-10","SNAPSHOT_6-3-10-beta1","RELEASE_6-3-9","RELEASE_6-3-9_5248","SNAPSHOT_6-3-9-rc3","SNAPSHOT_6-3-9-rc2","SNAPSHOT_6-3-9-rc1","RELEASE_6-3-8_5093","SNAPSHOT_6-3-8-rc3","SNAPSHOT_6-3-8-rc2","SNAPSHOT_6-3-8-rc1","RELEASE_6-3-7","SNAPSHOT_6-3-7-rc1","RELEASE_6-3-6","SNAPSHOT_6-3-6-rc5","SNAPSHOT_6-3-6-rc4","SNAPSHOT_6-3-6-rc3","SNAPSHOT_6-3-6-rc2","SNAPSHOT_6-3-6-rc1","RELEASE_6-3-5","SNAPSHOT_6-3-5-beta3","SNAPSHOT_6-3-5-beta2","SNAPSHOT_6-3-5-beta1","RELEASE_6-3-4","SNAPSHOT_6-3-4-rc2","SNAPSHOT_6-3-4-rc1","RELEASE_6-3-3","SNAPSHOT_6-3-3-rc2","SNAPSHOT_6-3-3-rc1","RELEASE_6-3-2","RELEASE_6-3-2_4678","SNAPSHOT_6-3-2-rc4","SNAPSHOT_6-3-2-rc3","SNAPSHOT_6-3-2-rc2","SNAPSHOT_6-3-2-rc1","RELEASE_6-3-1","SNAPSHOT_6-3-1-rc1","RELEASE_6-3-0","SNAPSHOT-6_2_9-rc10","SNAPSHOT-6_2_9-rc9","RELEASE_6-2-5","SNAPSHOT-6_2_9-rc8","SNAPSHOT-6_2_9-rc7","SNAPSHOT-6_2_9-rc6","SNAPSHOT-6_2_9-rc5","SNAPSHOT-6_2_9-rc4","SNAPSHOT-6_2_9-rc3","SNAPSHOT-6_2_9-rc2","SNAPSHOT-6_2_9-rc1","SNAPSHOT-6_2_6-pre9","SNAPSHOT-6_2_6-pre8","SNAPSHOT-6_2_6-pre7","SNAPSHOT-6_2_6-pre6","SNAPSHOT-6_2_6-pre5","SNAPSHOT_6-2-6-pre4","SNAPSHOT_6-2-6-pre3","before-automake","RELEASE_6-2-4","RELEASE_6-2-3","RELEASE_6-2-2","RELEASE_6-2-1","RELEASE_6-2-0","RELEASE_6-1-3","RELEASE_6-1-2","RELEASE_6-1-1","RELEASE_6-1-0","RELEASE_6-0-0","RELEASE_5-9-14","RELEASE_5-9-13","RELEASE_5-9-12","RELEASE_5-9-11","RELEASE_5-9-10","RELEASE_5-9-9","RELEASE_5-9-7","RELEASE_5-9-6","RELEASE_5-9-5","RELEASE_5-9-3","RELEASE_5-9-2","RELEASE_5-9-1","RELEASE_5-9-0","RELEASE_5-8-17","RELEASE_5-8-16","RELEASE_5-8-15","RELEASE_5-8-12","RELEASE_5-8-11","RELEASE_5-8-10","RELEASE_5-8-8","RELEASE_5-8-7","RELEASE_5-8-5","RELEASE_5-8-4","RELEASE_5-8-3","RELEASE_5-7-7","RELEASE_5-7-6","RELEASE_5-7-5","RELEASE_5-7-4","RELEASE_5-7-3","RELEASE_5-7-2","RELEASE_5-7-1","RELEASE_5-7-0","RELEASE_5-6-8","RELEASE_5-6-7","RELEASE_5-6-6","RELEASE_5-6-5","RELEASE_5-6-4","RELEASE_5-6-2","RELEASE_5-6-1","RELEASE_5-6-0","RELEASE_5-5-6","RELEASE_5-5-5","RELEASE_5-5-4","RELEASE_5-5-3","RELEASE_5-5-2","RELEASE_5-5-1","RELEASE_5-5-0","RELEASE_5-4-5","RELEASE_5-4-4","RELEASE_5-4-3","RELEASE_5-4-1","RELEASE_5-4-0","RELEASE_5-3-8","RELEASE_5-3-7","RELEASE_5-3-6","RELEASE_5-3-5","RELEASE_5-3-4","RELEASE_5-3-3","RELEASE_5-3-1","RELEASE_5-3-0","RELEASE_5-2-8","RELEASE_5-2-7","RELEASE_5-2-6","RELEASE_5-2-5","RELEASE_5-2-4","RELEASE_5-2-3","RELEASE_5-1-4","RELEASE_5-1-3","RELEASE_5-1-2","RELEASE_5-1-1","RELEASE_5-0-8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94184.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}