A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. (CVE-2026-94184)
A stack-based buffer overflow vulnerability exists in fetchmail when built with NTLM support. A malicious mail server can send a crafted NTLM Type 2 challenge causing fetchmail to write beyond a fixed stack buffer. This may lead to remote code execution, authentication failure, or process termination. The flaw affects fetchmail versions from 5.0.8 through 6.6.6. Mitigation includes rebuilding fetchmail without NTLM support or upgrading to version 6.6.7 or later.
AI Analysis
Technical Summary
CVE-2026-94184 describes a stack-based buffer overflow in fetchmail's NTLM authentication implementation. When fetchmail is built with NTLM support, a malicious or compromised mail server can send a specially crafted NTLM Type 2 challenge that causes fetchmail to overflow a fixed stack buffer during the construction of the NTLM authenticate response. This vulnerability can result in remote code execution depending on the stack frame layout or cause authentication failures or process termination under memory hardening conditions. The vulnerability affects fetchmail versions 5.0.8 through 6.6.6. Red Hat advisory confirms the issue and recommends either rebuilding fetchmail without NTLM support or upgrading to version 6.6.7 or later.
Potential Impact
The vulnerability allows a remote attacker controlling a mail server to potentially execute arbitrary code on the client running fetchmail if NTLM support is enabled. Alternatively, it may cause authentication failures or process crashes, impacting availability. The CVSS v3.1 score is 8.1, indicating high severity with network attack vector, high impact on confidentiality, integrity, and availability, and no privileges or user interaction required.
Mitigation Recommendations
Red Hat advises rebuilding fetchmail without NTLM support by omitting the --enable-NTLM option at configure time or upgrading to fetchmail version 6.6.7 or later. Confirm the absence of NTLM support by running 'fetchmail -V' and verifying that '+NTLM' is not listed. These are the recommended and effective mitigations.
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. (CVE-2026-94184)
Description
A stack-based buffer overflow vulnerability exists in fetchmail when built with NTLM support. A malicious mail server can send a crafted NTLM Type 2 challenge causing fetchmail to write beyond a fixed stack buffer. This may lead to remote code execution, authentication failure, or process termination. The flaw affects fetchmail versions from 5.0.8 through 6.6.6. Mitigation includes rebuilding fetchmail without NTLM support or upgrading to version 6.6.7 or later.
CVSS v3.1
Score 8.1high
Affected software
pkg:deb/ubuntu/fetchmail?arch=source&distro=xenialpkg:deb/ubuntu/fetchmail?arch=source&distro=bionicpkg:deb/ubuntu/fetchmail?arch=source&distro=focalpkg:deb/ubuntu/fetchmail?arch=source&distro=jammypkg:deb/ubuntu/fetchmail?arch=source&distro=noblepkg:deb/ubuntu/fetchmail?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94184 describes a stack-based buffer overflow in fetchmail's NTLM authentication implementation. When fetchmail is built with NTLM support, a malicious or compromised mail server can send a specially crafted NTLM Type 2 challenge that causes fetchmail to overflow a fixed stack buffer during the construction of the NTLM authenticate response. This vulnerability can result in remote code execution depending on the stack frame layout or cause authentication failures or process termination under memory hardening conditions. The vulnerability affects fetchmail versions 5.0.8 through 6.6.6. Red Hat advisory confirms the issue and recommends either rebuilding fetchmail without NTLM support or upgrading to version 6.6.7 or later.
Potential Impact
The vulnerability allows a remote attacker controlling a mail server to potentially execute arbitrary code on the client running fetchmail if NTLM support is enabled. Alternatively, it may cause authentication failures or process crashes, impacting availability. The CVSS v3.1 score is 8.1, indicating high severity with network attack vector, high impact on confidentiality, integrity, and availability, and no privileges or user interaction required.
Mitigation Recommendations
Red Hat advises rebuilding fetchmail without NTLM support by omitting the --enable-NTLM option at configure time or upgrading to fetchmail version 6.6.7 or later. Confirm the absence of NTLM support by running 'fetchmail -V' and verifying that '+NTLM' is not listed. These are the recommended and effective mitigations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-94184
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be23f7a7c54106eee98c
Added to database: 09/24/2026, 06:07:31 UTC
Last enriched: 09/24/2026, 06:20:34 UTC
Last updated: 09/24/2026, 14:49:23 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.