CVE-2026-107820: x64dbg-MCP Server vulnerable to pre-authentication denial of service through Content-Length integer overflow

Published Oct 9, 2026
·
Updated

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcpserver.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.

Affected Software

1 affected component
x64dbg x64dbg-MCP Server<1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade x64dbg-MCP Server to a version that resolves this vulnerability.

    Fixed in 1.2

Event History

Oct 9, 2026
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated attack?

Affected versions prior to 1.2 listen on 0.0.0.0 by default, making the HTTP service reachable by network clients where network controls permit it. Authentication does not protect against this issue because the vulnerable parsing occurs before token authentication.

2

What does an attacker need to do to trigger the denial of service?

An unauthenticated network client must send a request with a near-maximum Content-Length value. The value can trigger an unchecked usize addition overflow, causing a runtime panic in Debug and ReleaseSafe builds.

3

What is the practical impact on a running debugging session?

The panic terminates the entire x64dbg process, including its live debugging session. The overflowed value is only used in a comparison, so the reported impact is denial of service rather than memory corruption or code execution.

4

What should be done if an immediate upgrade is not possible?

Restrict network access to the MCP server so untrusted clients cannot reach its HTTP listener, particularly because affected versions bind to all interfaces by default. Upgrade to version 1.2 when possible, as it fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203