


Perceptive Security
SOC/SIEM Consultancy

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arb…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 20:05:47
Source:
nvd.nist.gov
Security Tools
A heap-based buffer overflow vulnerability in hashcat v7.1.2's PKZIP hash parser allows attackers to cause denial of service or execute arbitrary code through crafted PKZIP hash files. The vulnerability exists in the hex_to_binary function where attacker-controlled hex data is decoded into a fixed-size buffer without proper input validation. The issue affects multiple hashcat modules (17200, 17210, 17220, 17225, and 17230) when data_type_enum is less than or equal to 1. This vulnerability poses a significant risk as it can lead to arbitrary code execution in a widely-used password recovery tool.
Technical details
Mitigation steps:
Affected products:
hashcat
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42484
https://gist.github.com/sgInnora/107f2eb20367e47d58c911e38d56a91f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
