Description
x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.
Published: 2026-10-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An integer overflow occurs in the MCP Server’s handling of the 'Content-Length' header for inbound HTTP requests. The server parses an unbounded Content-Length value and uses it in unchecked usize addition before authentication. An attacker can send a value near the maximum unsigned integer, causing a runtime integer‑overflow panic that terminates the entire x64dbg process. Only a denial of service is possible; there is no memory corruption or code execution. The vulnerability is labeled CWE‑190.

Affected Systems

The affected product is x64dbg-MCP Server, a native Model Context Protocol plugin for the x64dbg debugger. Versions prior to 1.2 are vulnerable. The server binds to 0.0.0.0 by default, exposing its full debugging functionality over HTTP to any host that can reach the listening port. Users running older releases without changing this default configuration are at risk.

Risk and Exploitability

The CVSS base score is 5.3, indicating a moderate severity denial of service that can be triggered from a remote host without authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can craft a malicious HTTP request to trigger the overflow, making exploitation highly likely in environments where the MCP Server is exposed to untrusted networks. The impact is limited to terminating the debugging session rather than compromising the host, but the ability to disrupt service may be critical in production debugging workflows.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to v1.2 or later of x64dbg-MCP Server.
  • Reconfigure the MCP Server to bind only to localhost or a private interface instead of 0.0.0.0.
  • Block the MCP Server’s HTTP port from external networks using firewall rules or network segmentation.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.
Title x64dbg-MCP Server vulnerable to pre-authentication denial of service through Content-Length integer overflow
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:42:45.100Z

Reserved: 2026-10-08T21:23:59.823Z

Link: CVE-2026-107820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:03.703

Modified: 2026-10-09T18:17:03.703

Link: CVE-2026-107820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound