CVE-2026-32941 is a Remote Out-of-Memory (OOM) vulnerability affecting Sliver C2 framework versions 1.7.3 and below, specifically within its mTLS and WireGuard C2 transport layers. This medium-severity vulnerability (CVSS 6.5) allows an authenticated attacker or compromised implant to trigger an OS OOM kill by sending fabricated length prefixes, forcing the server to attempt allocating up to ~256 GiB of memory. Successful exploitation crashes the Sliver server, disrupting all active implant sessions and potentially impacting other processes on the host. There is currently no evidence of active exploitation, nor is public exploit code available, and community discussion surrounding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.3CPE matchmatch criteria | cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.