Technology · Go
github.com/bishopfox/sliver (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in github.com/bishopfox/sliver (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, GO-2026-4899 - Sliver: Nil Pointer Dereference in tunnelCloseHandler causes…, was published on 2 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest github.com/bishopfox/sliver (Go) vulnerabilities
- GO-2026-4899 - Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in…info
- CVE-2026-34227: BishopFox Sliver unauthenticated remote access in MCP interfacehighCVSS 8.8EPSS 0.5%
- Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attemptedmediumCVSS 4
- CVE-2026-32941: GO-2026-4723 - Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in…mediumCVSS 4EPSS 0.4%
- CVE-2026-29781: GO-2026-4609 - Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in…mediumCVSS 4EPSS 0.5%
- GO-2026-4548 - Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliverinfo
- Sliver has Potential Zip Bomb Denial of Service in GzipEncodermediumCVSS 4
- CVE-2026-25760: GO-2026-4445 - Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in…lowCVSS 3.1EPSS 0.5%
- CVE-2026-25791: GO-2026-4466 - Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in…lowCVSS 3.1EPSS 0.5%
- GO-2026-4280 - Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliverinfo
- Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder BypassmediumCVSS 4
- CVE-2025-27093: GO-2025-4079 - Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliverlowCVSS 3.1EPSS 0.2%
- CVE-2025-27090: GO-2025-3472 - SSRF in sliver teamserver in github.com/bishopfox/slivermediumCVSS 4EPSS 0.6%
- CVE-2023-34758: GO-2023-1866 - Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in…lowCVSS 3.1EPSS 0.6%
- CVE-2024-41111: GO-2024-2993 - Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliverlowCVSS 3.1EPSS 0.7%
Most severe github.com/bishopfox/sliver (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34227: BishopFox Sliver unauthenticated remote access in MCP interfacehighCVSS 8.8EPSS 0.5%
- CVE-2025-27090: GO-2025-3472 - SSRF in sliver teamserver in github.com/bishopfox/slivermediumCVSS 4EPSS 0.6%
- CVE-2026-29781: GO-2026-4609 - Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in…mediumCVSS 4EPSS 0.5%
- CVE-2026-32941: GO-2026-4723 - Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in…mediumCVSS 4EPSS 0.4%
- Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attemptedmediumCVSS 4
- Sliver has Potential Zip Bomb Denial of Service in GzipEncodermediumCVSS 4
- Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder BypassmediumCVSS 4
- CVE-2024-41111: GO-2024-2993 - Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliverlowCVSS 3.1EPSS 0.7%
- CVE-2023-34758: GO-2023-1866 - Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in…lowCVSS 3.1EPSS 0.6%
- CVE-2026-25760: GO-2026-4445 - Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in…lowCVSS 3.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/bishopfox/sliver (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver, 28 September 2026.