CVE-2026-107820
Last modified
CVE-2026-107820 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication.
Description
x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| duty1g | x64dbg-mcp-server | < 1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107820?
How severe is CVE-2026-107820?
How do I fix CVE-2026-107820?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107815MariaDB server is a community developed fork of MySQL server…8.5
- CVE-2026-107816MariaDB server is a community developed fork of MySQL server…6.4
- CVE-2026-107817MariaDB server is a community developed fork of MySQL server…4.4
- CVE-2026-107818MariaDB server is a community developed fork of MySQL server…8.4
- CVE-2026-107819MariaDB Connector/C is a C and C++ client library for connec…5.9
- CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable…4.3
- CVE-2026-107821MariaDB server is a community developed fork of MySQL server…8
- CVE-2026-107822MariaDB server is a community developed fork of MySQL server…6.4
- CVE-2026-107823MariaDB server is a community developed fork of MySQL server…7.2
- CVE-2026-107824x64dbg-MCP Server is a native Model Context Protocol (MCP) p…9.3
- CVE-2026-107825OWASP Coraza WAF is a golang modsecurity compatible web appl…4
- CVE-2026-107826OWASP Coraza WAF is a golang modsecurity compatible web appl…7.5
Are you affected by CVE-2026-107820?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
