CVE-2026-102507 Details
Description
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.
A denial-of-service vulnerability has been identified in the Sliver C2 framework, affecting versions 1.1.0 through 1.7.7. The issue arises from an unhandled panic in the operator gRPC handler, where an attacker controlling a compromised implant can crash the entire teamserver. This is achieved by returning a malformed or empty Download response, which triggers an out-of-bounds slice access in the Binject library's BinaryMagic function. The resulting panic propagates through the gRPC interceptor chain, terminating the server process and disrupting all connected operators and sessions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/h00die/sliver_1.7.7_DoS | [email protected] | ExploitTechnical Analysis |
| https://www.vulncheck.com/advisories/sliver-denial-of-service-via-pe-parser-slice-bounds-in-operator-rpc | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BishopFox Sliver | >= 1.1.0, <= 1.7.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion