CVE-2026-25791: Bishopfox Sliver

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated remote actor can repeatedly create sessions and drive memory exhaustion. This vulnerability is fixed in 1.7.0.

Affected products

  • Bishopfox Sliver: before 1.7.0 (fixed in 1.7.0)

Published 2026-02-09. Last modified 2026-06-17.