Executive brief
A vulnerability has been identified in TeamSpeak 3 Server, a popular voice communication platform used by gaming and corporate communities. An attacker with basic user access can send specifically crafted network requests to crash the server or cause it to become unstable. This can lead to service outages and require manual restarts to restore communication for all users.
Technical details
A use-after-free vulnerability exists in the 'process_resend_queue' function within the Connection State Management component of TeamSpeak 3 Server and SDK. The flaw is triggered by inconsistent handling of connection states when processing specially crafted network requests. An authenticated remote attacker can exploit this to cause memory corruption, leading to service instability or a complete server crash (Denial-of-Service). The issue is resolved in TeamSpeak 3 Server version 3.13.8 and TeamSpeak SDK version 3.5.0.
Affected products
- TeamSpeak TeamSpeak 3 Server <= 3.13.7
- TeamSpeak TeamSpeak SDK (Server-Side Integrations) <= 3.3.1
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
- 2026-05-27: patched