{"id":"GHSA-hjr9-wj7v-7hv8","aliases":["GO-2026-4280"],"url":"https://o3.security/vulnerability/GHSA-hjr9-wj7v-7hv8","summary":"Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass","details":"### Summary\nA specially crafted nonce routes unauthenticated requests through the NoEncoder path, where `startSessionHandler()` reads the entire request body without limits, allowing attacker-driven memory exhaustion and process crash.\n\n### Details\n- `server/encoders/encoders.go`: `EncoderFromNonce()` returns NoEncoder when `nonce % 65537 == 0` (lines 254-264); NoEncoder is a passthrough (`util/encoders/nop.go:22-32`).\n- `server/c2/http.go`: `anonymousHandler()` routes requests with any encoder (including NoEncoder) to `startSessionHandler()` (lines 551-562).\n- `server/c2/http.go`: `startSessionHandler()` uses `io.ReadAll(req.Body)` without a size cap (lines 564-643), unlike the authenticated path that uses `io.LimitedReader` (`readReqBody()`, lines 708-732).\n\n### PoC\nAn attacker could send an HTTP POST with a nonce that is a multiple of 65537 (e.g., ?q=65537) so it is handled by startSessionHandler() with a NoEncoder, and advertise a very large Content-Length while streaming data. Because this handler uses io.ReadAll(req.Body) without a size limit, the server is expected to allocate large amounts of memory and may exhaust available RAM, leading to process termination on typical deployments.\n\n### Impact\nUnauthenticated remote DoS: attacker can crash the Sliver HTTP listener, dropping all active sessions and locking out operators until restart. No credentials or non-default config required.","published":"2026-01-05T19:43:06Z","modified":"2026-02-03T03:13:59.249624Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/bishopfox/sliver","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/BishopFox/sliver/security/advisories/GHSA-hjr9-wj7v-7hv8"},{"type":"PACKAGE","url":"https://github.com/BishopFox/sliver"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T03:13:59.249624Z"}}