{"id":"GHSA-hjr9-wj7v-7hv8","summary":"Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass","details":"### Summary\nA specially crafted nonce routes unauthenticated requests through the NoEncoder path, where `startSessionHandler()` reads the entire request body without limits, allowing attacker-driven memory exhaustion and process crash.\n\n### Details\n- `server/encoders/encoders.go`: `EncoderFromNonce()` returns NoEncoder when `nonce % 65537 == 0` (lines 254-264); NoEncoder is a passthrough (`util/encoders/nop.go:22-32`).\n- `server/c2/http.go`: `anonymousHandler()` routes requests with any encoder (including NoEncoder) to `startSessionHandler()` (lines 551-562).\n- `server/c2/http.go`: `startSessionHandler()` uses `io.ReadAll(req.Body)` without a size cap (lines 564-643), unlike the authenticated path that uses `io.LimitedReader` (`readReqBody()`, lines 708-732).\n\n### PoC\nAn attacker could send an HTTP POST with a nonce that is a multiple of 65537 (e.g., ?q=65537) so it is handled by startSessionHandler() with a NoEncoder, and advertise a very large Content-Length while streaming data. Because this handler uses io.ReadAll(req.Body) without a size limit, the server is expected to allocate large amounts of memory and may exhaust available RAM, leading to process termination on typical deployments.\n\n### Impact\nUnauthenticated remote DoS: attacker can crash the Sliver HTTP listener, dropping all active sessions and locking out operators until restart. No credentials or non-default config required.","aliases":["GO-2026-4280"],"modified":"2026-02-03T03:13:59.249624Z","published":"2026-01-05T19:43:06Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-01-05T19:43:06Z","nvd_published_at":null,"cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/BishopFox/sliver/security/advisories/GHSA-hjr9-wj7v-7hv8"},{"type":"PACKAGE","url":"https://github.com/BishopFox/sliver"}],"affected":[{"package":{"name":"github.com/bishopfox/sliver","ecosystem":"Go","purl":"pkg:golang/github.com/bishopfox/sliver"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"last_affected":"1.5.44"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hjr9-wj7v-7hv8/GHSA-hjr9-wj7v-7hv8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}