PT-2026-109285 · Unknown · Agelanserver

CVE-2026-107839

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ageLANServer versions prior to 1.15.2
Description The bundled game server in ageLANServer contains a remote denial-of-service issue. The POST /game/cloud/getFileURL endpoint fails to limit the request body size or the number of elements in the attacker-controlled names JSON array. The server allocates response storage based directly on the length of this array using the make() function. Because the default configuration disables authentication, an unauthenticated remote client can obtain a session and send a crafted request that forces excessive memory allocation. This can lead to memory amplification, causing the server process to hang or be terminated by the kernel OOM (Out of Memory) killer, which disconnects all active players and makes the service unavailable until it is restarted.
Recommendations Update ageLANServer to version 1.15.2. As a temporary mitigation, enable authentication in the server configuration to prevent unauthenticated clients from accessing the vulnerable endpoint.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107839
GHSA-4JFQ-PMQ9-257H

Affected Products

Agelanserver