CVE-2026-102507 PUBLISHED

Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor BishopFox
Product sliver
Versions Default: unaffected
  • affected from 1.1.0 to 1.7.7 (incl.)

Credits

  • h00die finder
  • VulnCheck coordinator

References

Problem Types

  • Out-of-bounds Read CWE