
🚨 HIGH - Hydra NTLM Type-2 challenge stack buffer overflow (CVE-2026-56766) Hydra (thc-hydra) through 9.7 is vulnerable to a stack-based buffer overflow in its NTLM authentication handling used across multiple protocol modules when parsing NTLM Type-2 challenges. The root cause is improper bounds checking on a base64-encoded NTLM response that can exceed a fixed 500-byte stack buffer due to an excessively long domain string. Exploitation is server-side: a malicious or compromised server can return a crafted Type-2 challenge during NTLM negotiation to trigger the overflow without requiring local privileges on the client running Hydra. Successful exploitation can lead to remote code execution in the context of the Hydra process, especially on systems lacking stack protections, with potential for full host compromise depending on how Hydra is run. 👉 Affected: thc-hydra <= 9.7 | Upgrade to No fix yet - treat as suspicious
Post summary
The post announces a stack‑buffer overflow in thc‑hydra 9.7 triggered by crafted NTLM Type‑2 challenges, potentially allowing remote code execution, with no patch available yet.
