What happened
Verified via NVD REST API (published 2026-10-09): prior to version 1.2, src/core/mcp_server.zig parses an unbounded Content-Length in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication; a crafted near-maximum value triggers an integer-overflow panic that terminates the whole x64dbg process (CWE-190), limited to DoS.
Why it matters
Pairs with the critical unauthenticated-access flaw in the same MCP server: even without a code-execution payload, a trivial unauthenticated request destroys the active AI-assisted debugging session — availability impact on the agentic analysis workflow.
Attack vector
An unauthenticated network client supplies a near-maximum Content-Length value that is parsed unbounded and used in unchecked usize addition in wsRecv() before token authentication, triggering a runtime integer-overflow panic (Debug/ReleaseSafe builds) that kills the x64dbg process.
Affected systems
x64dbg-mcp-server < 1.2 (same MCP plugin; listens on 0.0.0.0 by default in affected versions)
Mitigation
Upgrade to version 1.2; advisory GHSA-4478-h5jv-647m / GHSA-jgj3-97w2-9v9r. Do not expose port 9094/9095 beyond localhost.