Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Rebuild fetchmail without --enable-NTLM (omit NTLM at configure time), or upgrade to fetchmail 6.6.7 or later. Confirm with `fetchmail -V` that the build does not list +NTLM.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. | |
| Title | Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01) | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-21T14:48:16.088Z
Reserved: 2026-09-21T01:48:54.590Z
Link: CVE-2026-94184
Updated: 2026-09-21T14:39:04.468Z
Status : Received
Published: 2026-09-21T15:17:38.547
Modified: 2026-09-21T15:17:38.547
Link: CVE-2026-94184
No data.
OpenCVE Enrichment
No data.
