CVE-2026-94184

Source
https://cve.org/CVERecord?id=CVE-2026-94184
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94184.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94184
Downstream
Published
2026-09-21T14:17:16Z
Modified
2026-09-24T03:47:49Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Details

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.

Affects v5.0.8 through v6.6.6.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-121"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94184.json"
}
References

Affected packages

Git / gitlab.com/fetchmail/fetchmail

Affected ranges

Type
GIT
Repo
https://gitlab.com/fetchmail/fetchmail
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "v5.0.8"
        },
        {
            "fixed":  "v6.6.6"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

6.*
6.5.0
6.5.0.beta1
6.5.0.beta10
6.5.0.beta2
6.5.0.beta3
6.5.0.beta4
6.5.0.beta5
6.5.0.beta6
6.5.0.beta7
6.5.0.beta8
6.5.0.beta9
6.5.0.dev20200711a
6.5.0.dev20200711b
6.5.0.rc1
6.5.0.rc2
6.5.1
6.5.1.rc1
6.5.2
6.5.3
6.5.4
6.5.5
6.5.5.rc1
6.5.6
6.5.7.rc1
6.6.0
6.6.0.rc1
6.6.0.rc2
6.6.0.rc3
6.6.1
6.6.2
6.6.3
6.6.4
6.6.5
6.6.6
Other
BRANCH_6-3
RELEASE_5-0-8
RELEASE_5-1-1
RELEASE_5-1-2
RELEASE_5-1-3
RELEASE_5-1-4
RELEASE_5-2-3
RELEASE_5-2-4
RELEASE_5-2-5
RELEASE_5-2-6
RELEASE_5-2-7
RELEASE_5-2-8
RELEASE_5-3-0
RELEASE_5-3-1
RELEASE_5-3-3
RELEASE_5-3-4
RELEASE_5-3-5
RELEASE_5-3-6
RELEASE_5-3-7
RELEASE_5-3-8
RELEASE_5-4-0
RELEASE_5-4-1
RELEASE_5-4-3
RELEASE_5-4-4
RELEASE_5-4-5
RELEASE_5-5-0
RELEASE_5-5-1
RELEASE_5-5-2
RELEASE_5-5-3
RELEASE_5-5-4
RELEASE_5-5-5
RELEASE_5-5-6
RELEASE_5-6-0
RELEASE_5-6-1
RELEASE_5-6-2
RELEASE_5-6-4
RELEASE_5-6-5
RELEASE_5-6-6
RELEASE_5-6-7
RELEASE_5-6-8
RELEASE_5-7-0
RELEASE_5-7-1
RELEASE_5-7-2
RELEASE_5-7-3
RELEASE_5-7-4
RELEASE_5-7-5
RELEASE_5-7-6
RELEASE_5-7-7
RELEASE_5-8-10
RELEASE_5-8-11
RELEASE_5-8-12
RELEASE_5-8-15
RELEASE_5-8-16
RELEASE_5-8-17
RELEASE_5-8-3
RELEASE_5-8-4
RELEASE_5-8-5
RELEASE_5-8-7
RELEASE_5-8-8
RELEASE_5-9-0
RELEASE_5-9-1
RELEASE_5-9-10
RELEASE_5-9-11
RELEASE_5-9-12
RELEASE_5-9-13
RELEASE_5-9-14
RELEASE_5-9-2
RELEASE_5-9-3
RELEASE_5-9-5
RELEASE_5-9-6
RELEASE_5-9-7
RELEASE_5-9-9
RELEASE_6-0-0
RELEASE_6-1-0
RELEASE_6-1-1
RELEASE_6-1-2
RELEASE_6-1-3
RELEASE_6-2-0
RELEASE_6-2-1
RELEASE_6-2-2
RELEASE_6-2-3
RELEASE_6-2-4
RELEASE_6-2-5
RELEASE_6-3-0
RELEASE_6-3-1
RELEASE_6-3-10
RELEASE_6-3-11
RELEASE_6-3-12
RELEASE_6-3-13
RELEASE_6-3-14
RELEASE_6-3-15
RELEASE_6-3-16
RELEASE_6-3-17
RELEASE_6-3-18
RELEASE_6-3-19
RELEASE_6-3-2
RELEASE_6-3-20
RELEASE_6-3-21
RELEASE_6-3-22
RELEASE_6-3-23
RELEASE_6-3-24
RELEASE_6-3-25
RELEASE_6-3-26
RELEASE_6-3-2_4678
RELEASE_6-3-3
RELEASE_6-3-4
RELEASE_6-3-5
RELEASE_6-3-6
RELEASE_6-3-7
RELEASE_6-3-8
RELEASE_6-3-8_5093
RELEASE_6-3-9
RELEASE_6-3-9_5248
SNAPSHOT-6-5-0-beta2
SNAPSHOT-6_2_6-pre5
SNAPSHOT-6_2_6-pre6
SNAPSHOT-6_2_6-pre7
SNAPSHOT-6_2_6-pre8
SNAPSHOT-6_2_6-pre9
SNAPSHOT-6_2_9-rc1
SNAPSHOT-6_2_9-rc10
SNAPSHOT-6_2_9-rc2
SNAPSHOT-6_2_9-rc3
SNAPSHOT-6_2_9-rc4
SNAPSHOT-6_2_9-rc5
SNAPSHOT-6_2_9-rc6
SNAPSHOT-6_2_9-rc7
SNAPSHOT-6_2_9-rc8
SNAPSHOT-6_2_9-rc9
SNAPSHOT-6_4_0_beta2
SNAPSHOT-6_4_0_beta3
SNAPSHOT-6_4_0_beta4
SNAPSHOT-6_4_0_beta5
SNAPSHOT-6_4_0_rc1
SNAPSHOT-6_4_0_rc2
SNAPSHOT-6_4_0_rc3
SNAPSHOT_6-2-6-pre3
SNAPSHOT_6-2-6-pre4
SNAPSHOT_6-3-1-rc1
SNAPSHOT_6-3-10-beta1
SNAPSHOT_6-3-15-beta1
SNAPSHOT_6-3-15-beta2
SNAPSHOT_6-3-15-beta3
SNAPSHOT_6-3-17-pre1
SNAPSHOT_6-3-18-pre1
SNAPSHOT_6-3-18-pre2
SNAPSHOT_6-3-19-pre1
SNAPSHOT_6-3-2-rc1
SNAPSHOT_6-3-2-rc2
SNAPSHOT_6-3-2-rc3
SNAPSHOT_6-3-2-rc4
SNAPSHOT_6-3-20-pre1
SNAPSHOT_6-3-20-rc2
SNAPSHOT_6-3-20-rc3
SNAPSHOT_6-3-3-rc1
SNAPSHOT_6-3-3-rc2
SNAPSHOT_6-3-4-rc1
SNAPSHOT_6-3-4-rc2
SNAPSHOT_6-3-5-beta1
SNAPSHOT_6-3-5-beta2
SNAPSHOT_6-3-5-beta3
SNAPSHOT_6-3-6-rc1
SNAPSHOT_6-3-6-rc2
SNAPSHOT_6-3-6-rc3
SNAPSHOT_6-3-6-rc4
SNAPSHOT_6-3-6-rc5
SNAPSHOT_6-3-7-rc1
SNAPSHOT_6-3-8-rc1
SNAPSHOT_6-3-8-rc2
SNAPSHOT_6-3-8-rc3
SNAPSHOT_6-3-9-rc1
SNAPSHOT_6-3-9-rc2
SNAPSHOT_6-3-9-rc3
SNAPSHOT_6-5-0-beta1
SNAPSHOT_6-5-0-beta3
SNAPSHOT_6-5-0-beta4
SNAPSHOT_6-5-0-beta5
SNAPSHOT_6-5-0-beta6
badmerge
before-automake

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94184.json"