{"schema_version":1,"title":"github.com/bishopfox/sliver (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in github.com/bishopfox/sliver (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, GO-2026-4899 - Sliver: Nil Pointer Dereference in tunnelCloseHandler causes…, was published on 2 April 2026.","url":"https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver","json_url":"https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":12},"latest":[{"slug":"go-2026-4899-sliver-nil-pointer-dereference-in-tunnelclosehandler-bd83eea8","title":"GO-2026-4899 - Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopf","severity":"info","exploited":false,"published_at":"2026-04-02T18:42:30+00:00","url":"https://junglewise.ai/threats/go-2026-4899-sliver-nil-pointer-dereference-in-tunnelclosehandler-bd83eea8"},{"cve":"CVE-2026-34227","cvss":8.8,"epss":0.0047,"slug":"cve-2026-34227-bishopfox-sliver-unauthenticated-remote-access-in-mcp-interface","title":"BishopFox Sliver unauthenticated remote access in MCP interface","severity":"high","exploited":false,"published_at":"2026-03-31T16:16:32.44+00:00","url":"https://junglewise.ai/threats/cve-2026-34227-bishopfox-sliver-unauthenticated-remote-access-in-mcp-interface"},{"cvss":4,"slug":"sliver-nil-pointer-dereference-in-tunnelclosehandler-causes-panic-when-df5d6c15","title":"Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted","severity":"medium","exploited":false,"published_at":"2026-03-29T15:25:42+00:00","url":"https://junglewise.ai/threats/sliver-nil-pointer-dereference-in-tunnelclosehandler-causes-panic-when-df5d6c15"},{"cve":"CVE-2026-32941","cvss":4,"epss":0.0044,"slug":"cve-2026-32941-sliver-vulnerable-to-authenticated-oom-via-memory-exhaustion-in","title":"GO-2026-4723 - Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2026-03-26T20:33:02+00:00","url":"https://junglewise.ai/threats/cve-2026-32941-sliver-vulnerable-to-authenticated-oom-via-memory-exhaustion-in"},{"cve":"CVE-2026-29781","cvss":4,"epss":0.0052,"slug":"cve-2026-29781-sliver-is-vulnerable-to-authenticated-nil-pointer-dereference","title":"GO-2026-4609 - Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2026-03-10T18:28:10+00:00","url":"https://junglewise.ai/threats/cve-2026-29781-sliver-is-vulnerable-to-authenticated-nil-pointer-dereference"},{"slug":"go-2026-4548-sliver-has-potential-zip-bomb-denial-of-service-in-2f7b0a08","title":"GO-2026-4548 - Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver","severity":"info","exploited":false,"published_at":"2026-02-25T23:07:04+00:00","url":"https://junglewise.ai/threats/go-2026-4548-sliver-has-potential-zip-bomb-denial-of-service-in-2f7b0a08"},{"cvss":4,"slug":"sliver-has-potential-zip-bomb-denial-of-service-in-gzipencoder-2fed74b2","title":"Sliver has Potential Zip Bomb Denial of Service in GzipEncoder","severity":"medium","exploited":false,"published_at":"2026-02-25T17:36:44+00:00","url":"https://junglewise.ai/threats/sliver-has-potential-zip-bomb-denial-of-service-in-gzipencoder-2fed74b2"},{"cve":"CVE-2026-25760","cvss":3.1,"epss":0.0052,"slug":"cve-2026-25760-sliver-vulnerable-to-website-path-traversal-arbitrary-file-read","title":"GO-2026-4445 - Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2026-02-17T18:09:06+00:00","url":"https://junglewise.ai/threats/cve-2026-25760-sliver-vulnerable-to-website-path-traversal-arbitrary-file-read"},{"cve":"CVE-2026-25791","cvss":3.1,"epss":0.005,"slug":"cve-2026-25791-sliver-has-dns-c2-otp-bypass-that-allows-unauthenticated-session","title":"GO-2026-4466 - Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2026-02-17T18:09:06+00:00","url":"https://junglewise.ai/threats/cve-2026-25791-sliver-has-dns-c2-otp-bypass-that-allows-unauthenticated-session"},{"slug":"go-2026-4280-sliver-vulnerable-to-pre-auth-memory-exhaustion-via-add7699f","title":"GO-2026-4280 - Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass in github.com/bishopfox/sliver","severity":"info","exploited":false,"published_at":"2026-01-12T17:39:39+00:00","url":"https://junglewise.ai/threats/go-2026-4280-sliver-vulnerable-to-pre-auth-memory-exhaustion-via-add7699f"},{"cvss":4,"slug":"sliver-vulnerable-to-pre-auth-memory-exhaustion-via-noencoder-bypass-f14c3de6","title":"Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass","severity":"medium","exploited":false,"published_at":"2026-01-05T19:43:06+00:00","url":"https://junglewise.ai/threats/sliver-vulnerable-to-pre-auth-memory-exhaustion-via-noencoder-bypass-f14c3de6"},{"cve":"CVE-2025-27093","cvss":3.1,"epss":0.0022,"slug":"cve-2025-27093-silver-has-unrestricted-traffic-between-wireguard-clients","title":"GO-2025-4079 - Silver has unrestricted traffic between Wireguard clients in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:15+00:00","url":"https://junglewise.ai/threats/cve-2025-27093-silver-has-unrestricted-traffic-between-wireguard-clients"},{"cve":"CVE-2025-27090","cvss":4,"epss":0.0063,"slug":"cve-2025-27090-ssrf-in-sliver-teamserver","title":"GO-2025-3472 - SSRF in sliver teamserver in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-27090-ssrf-in-sliver-teamserver"},{"cve":"CVE-2023-34758","cvss":3.1,"epss":0.0059,"slug":"cve-2023-34758-silver-vulnerable-to-mitm-attack-against-implants-due-to-a","title":"GO-2023-1866 - Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:35+00:00","url":"https://junglewise.ai/threats/cve-2023-34758-silver-vulnerable-to-mitm-attack-against-implants-due-to-a"},{"cve":"CVE-2024-41111","cvss":3.1,"epss":0.007,"slug":"cve-2024-41111-sliver-allows-authenticated-operator-to-server-remote-code","title":"GO-2024-2993 - Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2024-07-22T18:24:38+00:00","url":"https://junglewise.ai/threats/cve-2024-41111-sliver-allows-authenticated-operator-to-server-remote-code"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"github.com/bishopfox/sliver (Go)","slug":"github-com-bishopfox-sliver","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/github-com-bishopfox-sliver"},"most_severe":[{"cve":"CVE-2026-34227","cvss":8.8,"epss":0.0047,"slug":"cve-2026-34227-bishopfox-sliver-unauthenticated-remote-access-in-mcp-interface","title":"BishopFox Sliver unauthenticated remote access in MCP interface","severity":"high","exploited":false,"published_at":"2026-03-31T16:16:32.44+00:00","url":"https://junglewise.ai/threats/cve-2026-34227-bishopfox-sliver-unauthenticated-remote-access-in-mcp-interface"},{"cve":"CVE-2025-27090","cvss":4,"epss":0.0063,"slug":"cve-2025-27090-ssrf-in-sliver-teamserver","title":"GO-2025-3472 - SSRF in sliver teamserver in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-27090-ssrf-in-sliver-teamserver"},{"cve":"CVE-2026-29781","cvss":4,"epss":0.0052,"slug":"cve-2026-29781-sliver-is-vulnerable-to-authenticated-nil-pointer-dereference","title":"GO-2026-4609 - Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2026-03-10T18:28:10+00:00","url":"https://junglewise.ai/threats/cve-2026-29781-sliver-is-vulnerable-to-authenticated-nil-pointer-dereference"},{"cve":"CVE-2026-32941","cvss":4,"epss":0.0044,"slug":"cve-2026-32941-sliver-vulnerable-to-authenticated-oom-via-memory-exhaustion-in","title":"GO-2026-4723 - Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports in github.com/bishopfox/sliver","severity":"medium","exploited":false,"published_at":"2026-03-26T20:33:02+00:00","url":"https://junglewise.ai/threats/cve-2026-32941-sliver-vulnerable-to-authenticated-oom-via-memory-exhaustion-in"},{"cvss":4,"slug":"sliver-nil-pointer-dereference-in-tunnelclosehandler-causes-panic-when-df5d6c15","title":"Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted","severity":"medium","exploited":false,"published_at":"2026-03-29T15:25:42+00:00","url":"https://junglewise.ai/threats/sliver-nil-pointer-dereference-in-tunnelclosehandler-causes-panic-when-df5d6c15"},{"cvss":4,"slug":"sliver-has-potential-zip-bomb-denial-of-service-in-gzipencoder-2fed74b2","title":"Sliver has Potential Zip Bomb Denial of Service in GzipEncoder","severity":"medium","exploited":false,"published_at":"2026-02-25T17:36:44+00:00","url":"https://junglewise.ai/threats/sliver-has-potential-zip-bomb-denial-of-service-in-gzipencoder-2fed74b2"},{"cvss":4,"slug":"sliver-vulnerable-to-pre-auth-memory-exhaustion-via-noencoder-bypass-f14c3de6","title":"Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass","severity":"medium","exploited":false,"published_at":"2026-01-05T19:43:06+00:00","url":"https://junglewise.ai/threats/sliver-vulnerable-to-pre-auth-memory-exhaustion-via-noencoder-bypass-f14c3de6"},{"cve":"CVE-2024-41111","cvss":3.1,"epss":0.007,"slug":"cve-2024-41111-sliver-allows-authenticated-operator-to-server-remote-code","title":"GO-2024-2993 - Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2024-07-22T18:24:38+00:00","url":"https://junglewise.ai/threats/cve-2024-41111-sliver-allows-authenticated-operator-to-server-remote-code"},{"cve":"CVE-2023-34758","cvss":3.1,"epss":0.0059,"slug":"cve-2023-34758-silver-vulnerable-to-mitm-attack-against-implants-due-to-a","title":"GO-2023-1866 - Silver vulnerable to MitM attack against implants due to a cryptography vulnerability in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:35+00:00","url":"https://junglewise.ai/threats/cve-2023-34758-silver-vulnerable-to-mitm-attack-against-implants-due-to-a"},{"cve":"CVE-2026-25760","cvss":3.1,"epss":0.0052,"slug":"cve-2026-25760-sliver-vulnerable-to-website-path-traversal-arbitrary-file-read","title":"GO-2026-4445 - Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated) in github.com/bishopfox/sliver","severity":"low","exploited":false,"published_at":"2026-02-17T18:09:06+00:00","url":"https://junglewise.ai/threats/cve-2026-25760-sliver-vulnerable-to-website-path-traversal-arbitrary-file-read"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}