PatchSiren

hashcat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM hashcat CVE published 2026-08-22

CVE-2026-68768

A heap-based buffer overflow vulnerability exists in the hashcat tool, specifically in the outfile_write() function. This function is prone to a buffer overflow when assembling output into a fixed-size buffer without validating the accumulated length, potentially leading to memory corruption and process crashes. The vulnerability can be triggered by a crafted hash file containing an oversized username, wh [truncated]

HIGH hashcat CVE published 2026-08-22

CVE-2026-68766

CVE-2026-68766 hashcat restore file option injection allows attackers to append content to arbitrary files. This issue requires verification of affected versions and remediation from official sources. The vulnerability is caused by hashcat's failure to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. This c [truncated]

MEDIUM hashcat CVE published 2026-08-17

CVE-2026-68765

The CVE-2026-68765 vulnerability is a heap buffer overflow in the KeePass AESKDF/KDBX v4 module of hashcat master branch builds after v7.1.2. This vulnerability allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, potentially [truncated]