{"id":"CVE-2026-68767","title":"hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length","summary":"hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, po…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","cwe":["CWE-193"],"published":"2026-08-22","updated":"2026-08-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68767","references":[{"url":"https://github.com/hashcat/hashcat","label":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/blob/v7.1.2/src/filehandling.c#L1032-L1060","label":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249","label":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4739","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hashcat-through-off-by-one-out-of-bounds-heap-write-in-fgetl","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-08-23T04:42:15.506Z","epss":0.00128,"epssPercentile":0.02796,"slug":"CVE-2026-68767","body":"## Overview\n\nhashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}