Memory Allocation Flaw in ageLANServer Web Server for Age of Empires Games
CVE-2026-107839
7.5HIGH
What is CVE-2026-107839?
The ageLANServer web server, designed for offline multiplayer experiences in Age of Empires and Age of Mythology, suffers from a critical memory allocation issue. In versions prior to 1.15.2, an attacker can exploit the AoE3 POST /game/cloud/getFileURL handler due to the absence of a request body size limit and improper JSON name array handling. This vulnerability allows for oversized requests that lead to excessive memory usage, causing the server to crash or hang, which disrupts gameplay for active users. Users are encouraged to update to version 1.15.2 to mitigate this risk.
Affected Version(s)
ageLANServer < 1.15.2
