Denial of Service Vulnerability in x64dbg-MCP Server by Duty1g
CVE-2026-107820
5.3MEDIUM
What is CVE-2026-107820?
The x64dbg-MCP Server, a plugin designed for x64dbg, allows full debugger functionality over HTTP but contains a vulnerability in its content length parsing mechanism. Specifically, prior to version 1.2, it improperly handles unbounded Content-Length values while processing incoming requests. An unauthenticated attacker can exploit this flaw by sending a carefully crafted request, leading to a runtime integer-overflow panic which causes the x64dbg process to terminate, resulting in a denial of service. This issue is limited to affecting server availability and does not allow for memory corruption or arbitrary code execution. Upgrading to version 1.2 resolves this issue, ensuring continued secure operations.
Affected Version(s)
x64dbg-mcp-server < 1.2
