CVE-2026-29781 affects the Sliver command-and-control framework in version 1.7.3 and prior. The vulnerability is caused by a systemic lack of nil-pointer validation in the Sliver C2 server's Protobuf unmarshalling logic. An authenticated actor who has obtained valid implant credentials can send a signed message with required outer authentication intact while omitting nested fields expected by the server. During unmarshalling or subsequent handling, the server dereferences nil values and triggers an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport paths do not implement the panic-recovery middleware used by the HTTP transport, the panic is not contained to a single request and instead terminates the entire Sliver server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Go proof-of-concept exploit that remotely crashes a Bishop Fox Sliver C2 server by abusing a protobuf nil-pointer dereference in the BeaconRegister handler (CWE-476), described as CVE-2026-29781. The repo is minimal (4 files): README.md (advisory/steps), go.mod/go.sum (dependencies: bishopfox/sliver v1.15.16, hashicorp/yamux, protobuf, x/crypto), and mtls_poc.go (the exploit). mtls_poc.go implements a 5-stage network exploit over the Sliver mTLS transport: (1) loads implant-derived mTLS client cert/key and connects to a configurable endpoint (default 127.0.0.1:8888) with InsecureSkipVerify enabled; (2) writes the Yamux preface ("MUX/1") and opens a Yamux stream; (3) constructs a malicious sliverpb.BeaconRegister protobuf with the nested Register field omitted (nil), which the server later dereferences (beaconReg.Register.Name) without validation; (4) bypasses/replicates Sliver envelope signing by deterministically generating an Ed25519 signing key from the implant Age peer_private_key (SHA256("env-signing-v1:"+peer_private_key) as seed) and producing a minisign-like signature buffer; (5) sends signature, a little-endian uint32 length prefix, and the marshaled sliverpb.Envelope containing the malicious BeaconRegister. The expected outcome is an unrecovered panic in the server goroutine handling mTLS/Yamux traffic, terminating the entire Sliver server process and dropping all active sessions/operators. The exploit’s key capability is an infrastructure-level DoS/"kill-switch" against Sliver when the attacker/defender has captured an implant (or otherwise obtained implant mTLS credentials and the Age secret), enabling them to authenticate as an implant and deliver the crash packet.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.