{"id":"CVE-2026-102507","summary":"Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC","details":"Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.","modified":"2026-10-02T03:30:53.724957706Z","published":"2026-09-29T11:49:54.760Z","database_specific":{"cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102507.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102507.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102507"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sliver-denial-of-service-via-pe-parser-slice-bounds-in-operator-rpc"},{"type":"PACKAGE","url":"https://github.com/BishopFox/sliver"},{"type":"EVIDENCE","url":"https://github.com/h00die/sliver_1.7.7_DoS"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bishopfox/sliver","events":[{"introduced":"b3e005dd431841f864a7168baf78071565bbcd96"},{"last_affected":"0aa7e5bf962414823f12c3a8ea1f667f61b19ce2"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.7.7"}]}}],"versions":["v1.7.7","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.11","v1.6.10","v1.6.9","v1.6.8","v1.6.7","v1.6.6","v1.6.5","v1.6.4","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.30","v1.5.29","v1.5.28","v1.5.27","v1.5.26","v1.5.25","v1.5.23","v1.5.24","v1.5.22","v1.5.21","v1.5.20","v1.5.19","v1.5.18","v1.5.17","v1.5.16","v1.5.15","v1.5.14","v1.5.13","v1.5.12","v1.5.11","v1.5.10","v1.5.9","v1.5.7","v1.5.8","v1.5.6","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.21","v1.4.20","v1.4.19","v1.4.18","v1.4.17","v1.4.16","v1.4.15","v1.4.14","v1.4.13","v1.4.12","v1.4.10","v1.4.9","v1.4.8","v1.4.6","v1.4.7","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.0","v1.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102507.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}