cbcvebase.

Github.Com Bishopfox Sliver vulnerabilities

9 known vulnerabilities affecting github.com/bishopfox_sliver.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-34227P3MEDIUMCVSS 5.9≥ 0, < 1.7.42026-03-31
CVE-2026-34227 [MEDIUM] CWE-306 Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface A single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, `ntds.dit`) or destroying the entire compromised infrastructure, entirely through the operator's own browser.
ghsaosv
CVE-2026-25791P3HIGH≥ 0, < 1.6.122026-02-06
CVE-2026-25791 [HIGH] CWE-306 Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service ## Summary The DNS C2 listener accepts unauthenticated `TOTP` bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when `EnforceOTP` is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated
ghsaosv
CVE-2024-41111P3HIGH≥ 1.5.40, < 1.6.02024-07-18
CVE-2024-41111 [HIGH] CWE-74 Sliver Allows Authenticated Operator-to-Server Remote Code Execution Sliver Allows Authenticated Operator-to-Server Remote Code Execution ## Description Sliver version 1.6.0 (prerelease) is vulnerable to RCE on the teamserver by a low-privileged "operator" user. The RCE is as the system root user. ## Impact As described in a [past issue](https://github.com/BishopFox/sliver/issues/65), "there is a clear security boundary between the operator and server, an operator
ghsaosv
CVE-2026-25760P3MEDIUM≥ 0, < 1.6.112026-02-05
CVE-2026-25760 [MEDIUM] CWE-22 Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) ## Summary A Path Traversal vulnerability in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated **Path Traversal / arbitrary file read** issue, and it can expose credentials, configs, and keys. ## Affected Component - We
ghsaosv
CVE-2023-34758P3HIGHCVSS 8.1≥ 1.5.0, < 1.5.402023-06-21
CVE-2023-34758 [HIGH] CWE-327 Silver vulnerable to MitM attack against implants due to a cryptography vulnerability Silver vulnerable to MitM attack against implants due to a cryptography vulnerability ### Summary The current cryptography implementation in Sliver up to version 1.5.39 allows a MitM with access to the corresponding implant binary to execute arbitrary codes on implanted devices via intercepted and crafted responses. (Reserved CVE ID: CVE-2023-34758) ### Details Please see [the Po
ghsaosv
CVE-2026-29781P3LOW≥ 0, ≤ 1.7.32026-03-05
CVE-2026-29781 [LOW] CWE-476 Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers ## 1. Executive Summary A vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. B
ghsaosv
CVE-2026-32941P3MEDIUM≥ 0, ≤ 1.7.32026-03-17
CVE-2026-32941 [MEDIUM] CWE-770 Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports # Summary A Remote OOM (Out-of-Memory) vulnerability exists in the Sliver C2 server's mTLS and WireGuard C2 transport layer. The `socketReadEnvelope` and `socketWGReadEnvelope` functions trust an attacker-controlled 4-byte length prefix to allocate memory, with `ServerMaxMessageSize` al
ghsaosv
CVE-2025-27093P3MEDIUM≥ 0, < 1.5.442025-10-28
CVE-2025-27093 [MEDIUM] CWE-284 Silver has unrestricted traffic between Wireguard clients Silver has unrestricted traffic between Wireguard clients ### Summary Sliver's custom Wireguard netstack doesn't limit traffic between Wireguard clients, this could lead to: 1. Leaked/recovered keypair (from a beacon) being used to attack operators. 2. Port forwardings usable from other implants. ### Details 1. Sliver treat operators' Wireguard config and beacon/session's Wireguard config equally, they b
ghsaosv
CVE-2025-27090P4MEDIUM≥ 1.5.26, < 1.5.432025-02-19
CVE-2025-27090 [MEDIUM] CWE-918 SSRF in sliver teamserver SSRF in sliver teamserver ### Summary The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so ### Reproduction steps Run server ``` wget https://github.com/BishopFox/sliver/releases/download/v1.5.42/sliver-server_linux chmod +x sliver-server_linux ./sliver-server_linux ``` Generate binary ``` generate --mtls
ghsaosv
Github.Com Bishopfox Sliver vulnerabilities | cvebase