CVE-2026-42482Disclosure(hashcat / hashcat)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch hashcat hashcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or -k rule options used with password candidates of 128 or more characters. The vulnerability is caused by a bounds check that fails to account for the 2x expansion that occurs when password bytes are converted to hexadecimal.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hashcat

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
hashcat

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-05-01: 2Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-13: 305-0105-13
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure1Patch1
2026-05-134
Disclosure3General1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42482 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces the discovery of CVE‑2026‑42482, a critical flaw with a CVSS score of 9.8, but provides no proof of concept, exploitation details, or remediation guidance.

    1001042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42482 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A stack-based buffer overflow in mangletohexlower() and mangletohexupper() in src/rpcpu.c in hashcat v7.1.2 allows an attacker to cause a…

    Post summary

    CVE-2026-42482 is a critical stack-based buffer overflow in hashcat v7.1.2, disclosed with a CVSS score of 9.8 and detailed vulnerability information, but no PoC or exploit code is provided.

    1001042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42482 (CVSS 9.8) — hashcat hashcat. CVE: CVE-2026-42482 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical advisory for CVE-2026-42482, providing severity metrics but no PoC, exploit code or remediation details.

    1001045
    210 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-42482 — CVSS 9.8/10 ██████████ A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/kXKqTwXzDO

    Post summary

    CVE‑2026‑42482 is a critical stack‑based buffer overflow in hashcat v7.1.2, with a patch already released; no active exploitation is reported.

    1100077
    26 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42482-hashcat-hashcat #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text offers only a URL and hashtags about CVE-2026-42482, providing no explicit details on PoC, exploitation, or remediation.

    0001030
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42482 Stack-Based Buffer Overflow in Hashcat 7.1.2 Rule Processing Functions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42482

    Post summary

    The text introduces CVE-2026-42482 as a stack-based buffer overflow in Hashcat 7.1.2, detailing its technical nature without providing exploitation or patch information.

    0000061
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphashcathashcat7.1.2--

Explore more