Impact
An integer overflow occurs in the MCP Server’s handling of the 'Content-Length' header for inbound HTTP requests. The server parses an unbounded Content-Length value and uses it in unchecked usize addition before authentication. An attacker can send a value near the maximum unsigned integer, causing a runtime integer‑overflow panic that terminates the entire x64dbg process. Only a denial of service is possible; there is no memory corruption or code execution. The vulnerability is labeled CWE‑190.
Affected Systems
The affected product is x64dbg-MCP Server, a native Model Context Protocol plugin for the x64dbg debugger. Versions prior to 1.2 are vulnerable. The server binds to 0.0.0.0 by default, exposing its full debugging functionality over HTTP to any host that can reach the listening port. Users running older releases without changing this default configuration are at risk.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity denial of service that can be triggered from a remote host without authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can craft a malicious HTTP request to trigger the overflow, making exploitation highly likely in environments where the MCP Server is exposed to untrusted networks. The impact is limited to terminating the debugging session rather than compromising the host, but the ability to disrupt service may be critical in production debugging workflows.
OpenCVE Enrichment