{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "All OPENVAS SCAN models with Greenbone OS 5.0 to 25.0.5 and openvas-scanner v3.0 to v23.49.3 are subject to a stack buffer overflow caused by a malicious or compromised NASL vulnerability test (VT).\n\nA malicious or compromised NASL vulnerability test (VT) script can trigger a stack buffer overflow in the scanner.",
        "title": "Summary"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Greenbone AG\nNeumarkt 12\n49074 Osnabrück\nGermany\nwww.greenbone.net",
      "issuing_authority": "Security Response Team",
      "name": "Greenbone AG",
      "namespace": "https://www.greenbone.net/en/security-response-team/"
    },
    "title": "Greenbone Security Advisory 2026-03: NTLMv1_HASH Stack Buffer Overflow",
    "tracking": {
      "current_release_date": "2026-08-19T23:00:00.000Z",
      "generator": {
        "date": "2026-08-27T09:28:08.342Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.9"
        }
      },
      "id": "GBSA2026-03",
      "initial_release_date": "2026-08-19T23:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-19T23:00:00.000Z",
          "number": "1",
          "summary": "Problem identified by Tristan Madani (Talence Security) (2026-07-16), solved (2026-07-17), solution published as new Patch Level release GOS 25.0.6 (2026-08-06) and openvas-scanner release v23.49.4 (2026-07-17)"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "product_version_range",
        "name": "5.0 - 25.0.5",
        "product": {
          "name": "Greenbone OS 5.0 - 25.0.5",
          "product_id": "GOS 5.0 - 25.0.5"
        }
      },
      {
        "category": "product_version_range",
        "name": "3.0 - 23.49.3",
        "product": {
          "name": "openvas-scanner 3.0 - 23.49.3",
          "product_id": "openvas-scanner 3.0 - 23.49.3"
        }
      },
      {
        "category": "product_version",
        "name": "25.0.6",
        "product": {
          "name": "Greenbone OS 25.0.6",
          "product_id": "GOS 25.0.6"
        }
      },
      {
        "category": "product_version",
        "name": "23.49.4",
        "product": {
          "name": "openvas-scanner 23.49.4",
          "product_id": "openvas-scanner 23.49.4"
        }
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-81625",
      "cwe": {
        "id": "CWE-121",
        "name": "Stack-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Resolution made available with Greenbone OS 25.0.6 on 2026-08-06 and openvas--scanner v23.49.4 on 2026-06-17",
          "title": "Resolution"
        }
      ],
      "product_status": {
        "fixed": [
          "openvas-scanner 23.49.4",
          "GOS 25.0.6"
        ],
        "known_affected": [
          "openvas-scanner 3.0 - 23.49.3",
          "GOS 5.0 - 25.0.5"
        ],
        "recommended": [
          "openvas-scanner 23.49.4",
          "GOS 25.0.6"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-81625",
          "url": "https://nvd.nist.gov"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openvas-scanner 3.0 - 23.49.3",
            "GOS 5.0 - 25.0.5"
          ]
        }
      ],
      "title": "stack buffer overflow caused by a malicious or compromised NASL vulnerability test (VT)"
    }
  ]
}