Denial of Service Vulnerability in x64dbg-MCP Server by Duty1g
CVE-2026-107820

5.3MEDIUM

Key Information:

Vendor

Duty1g

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107820?

The x64dbg-MCP Server, a plugin designed for x64dbg, allows full debugger functionality over HTTP but contains a vulnerability in its content length parsing mechanism. Specifically, prior to version 1.2, it improperly handles unbounded Content-Length values while processing incoming requests. An unauthenticated attacker can exploit this flaw by sending a carefully crafted request, leading to a runtime integer-overflow panic which causes the x64dbg process to terminate, resulting in a denial of service. This issue is limited to affecting server availability and does not allow for memory corruption or arbitrary code execution. Upgrading to version 1.2 resolves this issue, ensuring continued secure operations.

Affected Version(s)

x64dbg-mcp-server < 1.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.