CVE-2026-68765
Last modified
CVE-2026-68765 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, allowing a maximal input to write up to 44 bytes past the buffer boundary into adjacent esalt fields and heap chunk metadata, potentially enabling heap corruption or memory access violations.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, allowing a maximal input to write up to 44 bytes past the buffer boundary into adjacent esalt fields and heap chunk metadata, potentially enabling heap corruption or memory access violations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hashcat | hashcat | >= ef52453de9523f6a010652847b61cb340ed5daa5, < 6f374c4ff7d5dc951530fbbbcf6b45e3c169b100 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68765?
How severe is CVE-2026-68765?
How do I fix CVE-2026-68765?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68758A low-privileged authenticated user may access restricted su…6.5
- CVE-2026-68759A holder of a valid integration credential may impersonate o…7.2
- CVE-2026-6876ServiceNow has remediated a sandbox escape security issue th…10
- CVE-2026-68760An unauthenticated user may bypass authentication under spec…5.3
- CVE-2026-68762In JetBrains Ktor before 3.4.1 potential DoS attack via WebS…5.9
- CVE-2026-68763Uncontrolled Resource Consumption vulnerability in Apache To…7.5
- CVE-2026-68766hashcat fails to restrict command-line options when parsing …7.8
- CVE-2026-68767hashcat's fgetl() function in src/filehandling.c writes a nu…6.1
- CVE-2026-68768hashcat contains a heap-based buffer overflow (out-of-bounds…6.1
- CVE-2026-68769Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-68770sentence-transformers contains a security control bypass vul…9.8
- CVE-2026-68771ComfyUI v0.23.0 contains an unsafe deserialization vulnerabi…9.8
Are you affected by CVE-2026-68765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
