CVE-2026-102507: Bishopfox Sliver
Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.
Affected products
- Bishopfox Sliver: from 1.1.0, up to and including 1.7.7
Published 2026-09-29. Last modified 2026-09-30.