


Perceptive Security
SOC/SIEM Consultancy

A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code vi…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 18:06:04
Source:
nvd.nist.gov
Security Tools
A heap-based buffer overflow vulnerability in hashcat v7.1.2's Kerberos hash parser allows attackers to cause denial of service or execute arbitrary code via crafted Kerberos hash files. The vulnerability occurs in module_hash_decode functions across multiple Kerberos-related modules where account_info_len is calculated from untrusted delimiter positions without proper validation before memcpy operations into fixed-size buffers. This represents a significant security risk for systems using the affected hashcat version for Kerberos hash processing.
Technical details
Mitigation steps:
Affected products:
hashcat
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42483
https://gist.github.com/sgInnora/107f2eb20367e47d58c911e38d56a91f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
