<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:49:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-257151</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257151</link>
      <description>EUVD-2026-257151</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257151</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27093</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27093</link>
      <description>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27093</guid>
    </item>
    <item>
      <title>GHSA-q8j9-34qf-7vq7 — Silver has unrestricted traffic between Wireguard clients</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q8j9-34qf-7vq7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/BishopFox/sliver&lt;/p&gt;
&lt;p&gt;### Summary
Sliver&amp;#39;s custom Wireguard netstack doesn&amp;#39;t limit traffic between Wireguard clients, this could lead to:
1. Leaked/recovered keypair (from a beacon) being used to attack operators.
2. Port forwardings usable from other implants.&lt;/p&gt;
&lt;p&gt;### Details
1. Sliver treat operators&amp;#39; Wireguard config and beacon/session&amp;#39;s Wireguard config equally, they both connect to the wireguard listener created from the CLI.&lt;/p&gt;
&lt;p&gt;2. The current netstack implementation does not filter traffic between clients. 
I think this piece of code handle traffic between clients, from experimental results clients can ping and connect to each other freely, and I didn&amp;#39;t see any filtering here either:
```
File: server\c2\wireguard.go
246: func socketWGWriteEnvelope(connection net.Conn, envelope *sliverpb.Envelope) error {
247: 	data, err := proto.Marshal(envelope)
248: 	if err != nil {
249: 		wgLog.Errorf(&amp;#34;Envelope marshaling error: %v&amp;#34;, err)
250: 		return err
251: 	}
252: 	dataLengthBuf := new(bytes.Buffer)
253: 	binary.Write(dataLengthBuf, binary.LittleEndian, uint32(len(data)))
254: 	connection.Write(dataLengthBuf.Bytes())
255: 	connection.Write(data)
256: 	return nil
257: }
258:&lt;/p&gt;
&lt;p&gt;```
3. The docs says to use a Wireguard clients and operator wg-config to connect to the same WG listener as beacons:
https://sliver.sh/docs?name=Port%20Forwarding&lt;/p&gt;
&lt;p&gt;4. If the operator uses official wireguard clients that integrates with the OS&amp;#39;s netstack (I&amp;#39;m using the [Windows client](https://www.wireguard.com/install/)) then thei…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/BishopFox/sliver&lt;/p&gt;
&lt;p&gt;### Summary
Sliver&amp;#39;s custom Wireguard netstack doesn&amp;#39;t limit traffic between Wireguard clients, this could lead to:
1. Leaked/recovered keypair (from a beacon) being used to attack operators.
2. Port forwardings usable from other implants.&lt;/p&gt;
&lt;p&gt;### Details
1. Sliver treat operators&amp;#39; Wireguard config and beacon/session&amp;#39;s Wireguard config equally, they both connect to the wireguard listener created from the CLI.&lt;/p&gt;
&lt;p&gt;2. The current netstack implementation does not filter traffic between clients. 
I think this piece of code handle traffic between clients, from experimental results clients can ping and connect to each other freely, and I didn&amp;#39;t see any filtering here either:
```
File: server\c2\wireguard.go
246: func socketWGWriteEnvelope(connection net.Conn, envelope *sliverpb.Envelope) error {
247: 	data, err := proto.Marshal(envelope)
248: 	if err != nil {
249: 		wgLog.Errorf(&amp;#34;Envelope marshaling error: %v&amp;#34;, err)
250: 		return err
251: 	}
252: 	dataLengthBuf := new(bytes.Buffer)
253: 	binary.Write(dataLengthBuf, binary.LittleEndian, uint32(len(data)))
254: 	connection.Write(dataLengthBuf.Bytes())
255: 	connection.Write(data)
256: 	return nil
257: }
258:&lt;/p&gt;
&lt;p&gt;```
3. The docs says to use a Wireguard clients and operator wg-config to connect to the same WG listener as beacons:
https://sliver.sh/docs?name=Port%20Forwarding&lt;/p&gt;
&lt;p&gt;4. If the operator uses official wireguard clients that integrates with the OS&amp;#39;s netstack (I&amp;#39;m using the [Windows client](https://www.wireguard.com/install/)) then thei…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q8j9-34qf-7vq7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</guid>
    </item>
  </channel>
</rss>
