<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:58:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275009</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275009</link>
      <description>EUVD-2026-275009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275009</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29781</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29781</link>
      <description>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server&amp;#39;s Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure &amp;#34;kill-switch,&amp;#34; instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations. At time of publication, there are no publicly available patches.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server&amp;#39;s Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure &amp;#34;kill-switch,&amp;#34; instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations. At time of publication, there are no publicly available patches.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29781</guid>
    </item>
    <item>
      <title>GHSA-hx52-cv84-jr5v — Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hx52-cv84-jr5v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary
A vulnerability exists in the Sliver C2 server&amp;#39;s Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure &amp;#34;kill-switch,&amp;#34; instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations.&lt;/p&gt;
&lt;p&gt;## 2. Vulnerability Details
### 2.0 Technical Workflow: From Envelope to Handler
Sliver encapsulates all C2 traffic in a generic `sliverpb.Envelope`, which acts as a routing wrapper. When the server receives an Envelope with `Type = 53` (MsgBeaconRegister), the internal router strips the envelope and passes the raw `Data` bytes directly to the vulnerable `handlers.beaconRegisterHandler(implantConn, data)`. This flow is consistent across all transports, but the **error handling** of the transport itself determines the final impact.&lt;/p&gt;
&lt;p&gt;### 2.1 BeaconRegister Nil-Pointer Dereference
- **Vulnerability Type:** Remote Denial of Service via Nil-Pointer Dereference ([CWE-476](https://cwe.mitre.org/data/definitions/476.html))
- **Component:** `server/handlers/beacons.go`
- **Af…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary
A vulnerability exists in the Sliver C2 server&amp;#39;s Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure &amp;#34;kill-switch,&amp;#34; instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations.&lt;/p&gt;
&lt;p&gt;## 2. Vulnerability Details
### 2.0 Technical Workflow: From Envelope to Handler
Sliver encapsulates all C2 traffic in a generic `sliverpb.Envelope`, which acts as a routing wrapper. When the server receives an Envelope with `Type = 53` (MsgBeaconRegister), the internal router strips the envelope and passes the raw `Data` bytes directly to the vulnerable `handlers.beaconRegisterHandler(implantConn, data)`. This flow is consistent across all transports, but the **error handling** of the transport itself determines the final impact.&lt;/p&gt;
&lt;p&gt;### 2.1 BeaconRegister Nil-Pointer Dereference
- **Vulnerability Type:** Remote Denial of Service via Nil-Pointer Dereference ([CWE-476](https://cwe.mitre.org/data/definitions/476.html))
- **Component:** `server/handlers/beacons.go`
- **Af…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hx52-cv84-jr5v</guid>
    </item>
  </channel>
</rss>
