Executive brief
A vulnerability has been identified in TeamSpeak 3 Server, a popular voice communication platform used by gaming communities and businesses. An attacker can send specially crafted network data to crash the server, leading to a total loss of availability for users. This could disrupt operations or community activities until the server is manually restarted or patched.
Technical details
A heap-based buffer overflow exists in the ECC Key Parser component of TeamSpeak 3 Server. The vulnerability is triggered when the server processes specially crafted Elliptic Curve Cryptography (ECC) keys sent over the network. An unauthenticated remote attacker can exploit this flaw to cause a denial-of-service (DoS) condition, resulting in service instability or server crashes. The issue is fixed in TeamSpeak 3 Server version 3.13.8.
Affected products
- TeamSpeak TeamSpeak 3 Server <= 3.13.7
Timeline
- 2026-05-27: disclosed
- 2026-05-27: patched: Fixed in version 3.13.8
- 2026-05-27: advisory