Vulnerability  ·  2026-10-10

x64dbg-MCP Server unauthenticated integer-overflow DoS can crash the debugger process (CVSS 5.3)

VulnerabilityMedium impactGlobalCVE-2026-107820
Verified via NVD REST API (published 2026-10-09): prior to version 1.2, src/core/mcp_server.zig parses an unbounded Content-Length in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication; a crafted near-maximum value triggers an integer-overflow panic that terminates the whole x64dbg process (CWE-190), limited to DoS.
Pairs with the critical unauthenticated-access flaw in the same MCP server: even without a code-execution payload, a trivial unauthenticated request destroys the active AI-assisted debugging session — availability impact on the agentic analysis workflow.
An unauthenticated network client supplies a near-maximum Content-Length value that is parsed unbounded and used in unchecked usize addition in wsRecv() before token authentication, triggering a runtime integer-overflow panic (Debug/ReleaseSafe builds) that kills the x64dbg process.
x64dbg-mcp-server < 1.2 (same MCP plugin; listens on 0.0.0.0 by default in affected versions)
Upgrade to version 1.2; advisory GHSA-4478-h5jv-647m / GHSA-jgj3-97w2-9v9r. Do not expose port 9094/9095 beyond localhost.
NVD CVE-2026-107820GitHub Security Advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →