Impact
The flaw is an unbounded allocation of a JSON names array inside the AoE3 Cloud getFileURL handler. An attacker can send a POST request with an arbitrarily large array that causes the server to allocate excessive memory, leading to a crash or hang. The result is a denial of service for all connected players, as the service must be restarted to recover. The weakness corresponds to CWE-400 and does not grant code execution or data exfiltration.
Affected Systems
The affected product is luskaner's ageLANServer, a cross‑platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology titles. Any installation using a version prior to 1.15.2 is vulnerable, including 1.15.1 and earlier releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity and the EPSS score is not available, suggesting the exploitation probability has not been quantified yet. The vulnerability is remotely exploitable with no authentication required; an attacker can target the publicly reachable POST /game/cloud/getFileURL endpoint from any network. Because the attack merely drains memory resources, it works against any instance of the vulnerable service regardless of platform. The lack of a KEV listing means it is not yet a known exploited vulnerability, but the high severity and absence of a request size limit make it a top concern for publicly exposed servers.
OpenCVE Enrichment