CVE-2026-68767: Hashcat
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.
Affected products
- Hashcat Hashcat: up to and including 7.1.2
Published 2026-08-22. Last modified 2026-09-24.