github.com/bishopfox/sliver
Adversary Emulation Framework
Activity
- Latest release
- 1w ago
- Total releases
- 64
- Cadence
- ~9 days
- Last 12 months
- 21
Reach
- Stars
- 11.8k
Details
- First release
- Jan 20, 2019
| Version | Released | |
|---|---|---|
v1.7.7
patch
6 CVEs
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.7
patch
Dependencies (85)
+ 77 more |
|
v1.7.6
patch
6 CVEs
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.6
patch
Dependencies (84)
+ 76 more |
|
v1.7.5
patch
6 CVEs
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.5
patch
Dependencies (82)
+ 74 more |
|
v1.7.4
minor
6 CVEs
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.4
minor
Dependencies (82)
+ 74 more |
|
v1.7.3
patch
7 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.3
patch
Dependencies (77)
+ 69 more |
|
v1.7.2
patch
7 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.2
patch
Dependencies (77)
+ 69 more |
|
v1.7.1
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.1
patch
Dependencies (77)
+ 69 more |
|
v1.7.0
minor
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.0
minor
Dependencies (76)
+ 68 more |
|
v1.6.11
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.11
patch
Dependencies (73)
+ 65 more |
|
v1.6.10
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.10
patch
Dependencies (73)
+ 65 more |
|
v1.6.9
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.9
patch
Dependencies (69)
+ 61 more |
|
v1.6.8
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.8
patch
Dependencies (65)
+ 57 more |
|
v1.6.7
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.7
patch
Dependencies (64)
+ 56 more |
|
v1.6.6
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.6
patch
Dependencies (63)
+ 55 more |
|
v1.6.5
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.5
patch
Dependencies (63)
+ 55 more |
|
v1.6.4
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.4
patch
Dependencies (63)
+ 55 more |
|
v1.6.3
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.3
patch
Dependencies (63)
+ 55 more |
|
v1.6.2
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.2
patch
Dependencies (63)
+ 55 more |
|
v1.6.1
minor
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.1
minor
Dependencies (62)
+ 54 more |
|
v1.6.0
minor
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.0
minor
Dependencies (61)
+ 53 more |
|
v1.5.44
patch
9 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.5.44
patch
Dependencies (50)
+ 42 more |
|
v1.5.42
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.5.42
patch
Dependencies (50)
+ 42 more |
|
v1.5.41
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.5.41
patch
Dependencies (50)
+ 42 more |
|
v1.5.39
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.39
patch
Dependencies (49)
+ 41 more |
|
v1.5.34
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.34
patch
Dependencies (49)
+ 41 more |
|
v1.5.32
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.32
patch
Dependencies (50)
+ 42 more |
|
v1.5.30
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.30
patch
Dependencies (49)
+ 41 more |
|
v1.5.29
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.29
patch
Dependencies (50)
+ 42 more |
|
v1.5.27
patch
11 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27090
GO-2025-3472
GHSA-fh4v-v779-4g2w
Mar 03, 2025
SSRF in sliver teamserver in github.com/bishopfox/sliver SSRF in sliver teamserver in github.com/bishopfox/sliver Fixed in
1.5.43
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.27
patch
Dependencies (50)
+ 42 more |
|
v1.5.24
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.24
patch
Dependencies (44)
+ 36 more |
|
v1.5.22
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.22
patch
Dependencies (44)
+ 36 more |
|
v1.5.18
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.18
patch
Dependencies (44)
+ 36 more |
|
v1.5.16
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.16
patch
Dependencies (44)
+ 36 more |
|
v1.15.16
minor
6 CVEs
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41111
GO-2024-2993
GHSA-hc5w-gxxr-w8x8
Jul 22, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.0. References
Updated Aug 19, 2024 · Source: OSV.dev |
v1.15.16
minor
Dependencies (44)
+ 36 more |
|
v1.5.14
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.14
patch
Dependencies (44)
+ 36 more |
|
v1.5.13
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.13
patch
Dependencies (44)
+ 36 more |
|
v1.5.11
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.11
patch
Dependencies (44)
+ 36 more |
|
v1.5.7
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (44)
+ 36 more |
|
v1.5.4
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.4
patch
Dependencies (44)
+ 36 more |
|
v1.5.3
patch
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.3
patch
Dependencies (44)
+ 36 more |
|
v1.5.2
minor
10 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4280
GHSA-hjr9-wj7v-7hv8
Jan 12, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-34758
GO-2023-1866
CVE-2023-35170
GHSA-8jxm-xp43-qh3q
Aug 20, 2024
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver Fixed in
1.5.40
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.2
minor
Dependencies (44)
+ 36 more |
|
v1.4.19
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.19
patch
Dependencies (36)
+ 28 more |
|
v1.4.18
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.18
patch
Dependencies (36)
+ 28 more |
|
v1.4.17
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.17
patch
Dependencies (36)
+ 28 more |
|
v1.4.15
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.15
patch
Dependencies (35)
+ 27 more |
|
v1.4.14
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.14
patch
Dependencies (35)
+ 27 more |
|
v1.4.13
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.13
patch
Dependencies (35)
+ 27 more |
|
v1.4.12
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.12
patch
Dependencies (35)
+ 27 more |
|
v1.4.10
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.10
patch
Dependencies (33)
+ 25 more |
|
v1.4.9
patch
8 CVEs
CVE-2026-34227
GO-2026-5175
GHSA-6fpf-248c-m7wm
Jun 25, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface in github.com/bishopfox/sliver Fixed in
1.7.4
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4899
GHSA-c279-989m-238f
Apr 02, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-32941
GO-2026-4723
GHSA-97vp-pwqj-46qc
Mar 26, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-29781
GO-2026-4609
GHSA-hx52-cv84-jr5v
Mar 10, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver Updated Mar 23, 2026 · Source: OSV.dev
GO-2026-4548
GHSA-2phg-qgmm-r638
Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver Fixed in
1.7.2
References Updated Feb 25, 2026 · Source: OSV.dev
CVE-2026-25760
GO-2026-4445
GHSA-2286-hxv5-cmp2
Feb 17, 2026
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver Fixed in
1.6.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-25791
GO-2026-4466
GHSA-wxrw-gvg8-fqjp
Feb 17, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/bishopfox/sliver before v1.6.12. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-27093
GO-2025-4079
GHSA-q8j9-34qf-7vq7
Nov 05, 2025
Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver Fixed in
1.5.44
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.9
patch
Dependencies (33)
+ 25 more |