{"id":"CVE-2026-94184","published":"2026-09-21T15:17:38.547","lastModified":"2026-09-22T04:18:02.670","description":"A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.\n\nAffects v5.0.8 through v6.6.6.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-121"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-94184","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537395","tags":[]},{"url":"https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92","tags":[]},{"url":"https://www.fetchmail.info/fetchmail-SA-2026-01.txt","tags":[]},{"url":"https://www.openwall.com/lists/oss-security/2026/06/27/8","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a stack-based buffer overflow in fetchmail when NTLM support is enabled, allowing a malicious server to potentially execute arbitrary code or cause service disruption.","exploitability":"Exploitation requires a compromised or malicious mail server advertising NTLM authentication and sending a crafted challenge; this is moderately difficult given the need for specific conditions.","blast_radius":"If exploited, the impact could be severe, leading to remote code execution on affected systems, potentially compromising the entire network.","remediation":"Update fetchmail to versions later than v6.6.7 or disable NTLM support if not needed.","tags":["rce","auth-bypass","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:07:56.889Z"}}