Denial of Service Vulnerability in Sliver C2 Framework by h00die
CVE-2026-102507
Key Information:
Badges
What is CVE-2026-102507?
The Sliver C2 Framework versions 1.7.7 and earlier contain a vulnerability in the operator gRPC handler that allows an attacker to crash the entire teamserver. By sending malformed or empty Download responses from a compromised implant, attackers can trigger an unhandled panic through the operator gRPC interceptor chain. This leads to an out-of-bounds slice access in the Binject library's BinaryMagic function, causing the server process to terminate and impacting all connected operators.
Affected Version(s)
sliver 1.1.0 <= 1.7.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved