{"apiVersion":"1.0","identifier":"CVE-2026-68768","description":"hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process.","publishedAt":"2026-08-22T15:16:20","lastModifiedAt":"2026-08-24T19:16:44","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68768","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","epssProbability":0.00141,"riskScore":0.62,"affectedProduct":"hashcat","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-68768","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-68768","en":"https://www.redsauce.net/en/cves/CVE-2026-68768","fr":"https://www.redsauce.net/fr/cves/CVE-2026-68768","pt":"https://www.redsauce.net/pt/cves/CVE-2026-68768","de":"https://www.redsauce.net/de/cves/CVE-2026-68768","sk":"https://www.redsauce.net/sk/cves/CVE-2026-68768","el":"https://www.redsauce.net/el/cves/CVE-2026-68768"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-68768"}}