Memory Allocation Flaw in ageLANServer Web Server for Age of Empires Games
CVE-2026-107839

7.5HIGH

Key Information:

Vendor

Luskaner

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107839?

The ageLANServer web server, designed for offline multiplayer experiences in Age of Empires and Age of Mythology, suffers from a critical memory allocation issue. In versions prior to 1.15.2, an attacker can exploit the AoE3 POST /game/cloud/getFileURL handler due to the absence of a request body size limit and improper JSON name array handling. This vulnerability allows for oversized requests that lead to excessive memory usage, causing the server to crash or hang, which disrupts gameplay for active users. Users are encouraged to update to version 1.15.2 to mitigate this risk.

Affected Version(s)

ageLANServer < 1.15.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.