Junglewise Threat Intelligence

CVE-2026-4391: TeamSpeak 3 Server heap overflow in ECC Key Parser

CVE-2026-4391 · Severity: medium · CVSS 5.3 · Published 2026-05-27

Executive brief

A vulnerability has been identified in TeamSpeak 3 Server, a popular voice communication platform used by gaming communities and businesses. An attacker can send specially crafted network data to crash the server, leading to a total loss of availability for users. This could disrupt operations or community activities until the server is manually restarted or patched.

Technical details

A heap-based buffer overflow exists in the ECC Key Parser component of TeamSpeak 3 Server. The vulnerability is triggered when the server processes specially crafted Elliptic Curve Cryptography (ECC) keys sent over the network. An unauthenticated remote attacker can exploit this flaw to cause a denial-of-service (DoS) condition, resulting in service instability or server crashes. The issue is fixed in TeamSpeak 3 Server version 3.13.8.

Affected products

  • TeamSpeak TeamSpeak 3 Server <= 3.13.7

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: patched: Fixed in version 3.13.8
  • 2026-05-27: advisory

References