CVE-2026-94184

8.1

Red Hat · Fetchmail

A stack-based buffer overflow in fetchmail's NTLM authentication allows a malicious mail server to potentially trigger remote code execution via a crafted Type 2 challenge.

Executive summary

A high-severity stack-based buffer overflow in the fetchmail utility, affecting versions 5.0.8 through 6.6.6, poses a critical risk of remote code execution if a server is compromised or malicious.

Vulnerability

The vulnerability is a stack-based buffer overflow (CWE-121) occurring within the NTLM authentication handler. An unauthenticated attacker operating a malicious mail server can send a crafted Type 2 challenge, forcing the application to write beyond allocated stack memory during the response construction process.

Business impact

The potential for remote code execution represents a severe threat to operational integrity and data confidentiality. Given the CVSS score of 8.1, this vulnerability allows an attacker to gain unauthorized control over the system, potentially leading to total system compromise, data exfiltration, or lateral movement within the network.

Remediation

Immediate Action: Monitor the official Red Hat security advisory and fetchmail project repositories for the release of a patched version, and apply the update immediately upon availability.

Proactive Monitoring: Review mail server logs for unusual connection attempts or authentication errors that may indicate an interaction with a malicious mail server.

Compensating Controls: Restrict outbound mail server connectivity to trusted, internal, or known-safe endpoints to minimize exposure to potential malicious server challenges.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing fetchmail for mail retrieval should prioritize identifying the version currently in use across their infrastructure. While there is no current evidence of active exploitation, the potential for remote code execution in a core mail utility requires a proactive stance, including monitoring vendor channels and preparing for an emergency update cycle as soon as the patch is confirmed.

More Red Hat CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Upstream acknowledges Tristan Madani as the original reporter., per the CVE Program record.