{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cyrus-sasl/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cyrus_sasl_project:cyrus_sasl:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107161"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cyrus SASL"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-corruption"],"_cs_type":"advisory","_cs_vendors":["Cyrus SASL"],"content_html":"\u003cp\u003eCVE-2026-107161 identifies a critical heap-based buffer overflow vulnerability within the Cyrus SASL library, specifically affecting the DIGEST-MD5 plugin. The flaw resides in the add_to_challenge() function, which incorrectly calculates the required buffer size for challenge/response fields. The calculation occurs prior to the application of DIGEST-MD5 quoting, which escapes special characters and expands the string length. Consequently, the library allocates an insufficient buffer, which is subsequently passed to strcat(), resulting in a heap-based out-of-bounds write.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is triggered when a client application, utilizing the affected version of Cyrus SASL, connects to a malicious or compromised server that sends a crafted challenge field (e.g., realm or nonce). The resulting memory corruption typically causes the client application to crash, though the primitive may support arbitrary code execution in specific environments. Because the vulnerability exists within the client-side parsing logic, any application linking against the vulnerable version of Cyrus SASL for authentication is potentially at risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to a denial of service through application crashes. Given the nature of the heap-based buffer overflow, there is a risk of arbitrary code execution, which could allow an attacker to compromise the host system running the client-side software. This vulnerability affects any environment using Cyrus SASL for authentication, including enterprise mail servers, directory services, and various network client tools.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection and mitigation should focus on upgrading the library and monitoring for application instability.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Cyrus SASL library to the patched version once released by the vendor or package maintainer.\u003c/li\u003e\n\u003cli\u003eMonitor application logs and system event logs (such as Windows Event Viewer or Linux systemd journal) for frequent crash dumps (SIGSEGV or access violations) originating from services utilizing Cyrus SASL.\u003c/li\u003e\n\u003cli\u003eAudit client-side network connections to verify that they are connecting only to known-trusted and authenticated servers to mitigate the risk of a malicious server triggering the flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T20:45:26Z","date_published":"2026-10-07T20:45:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cyrus-sasl-overflow/","summary":"A heap-based buffer overflow in the Cyrus SASL DIGEST-MD5 plugin, tracked as CVE-2026-107161, allows remote malicious servers to cause memory corruption in client applications.","title":"Heap-based Buffer Overflow in Cyrus SASL DIGEST-MD5 Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cyrus-sasl-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cyrus SASL","version":"https://jsonfeed.org/version/1.1"}