PT-2026-109285 · Unknown · Agelanserver
CVE-2026-107839
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ageLANServer versions prior to 1.15.2
Description
The bundled game server in ageLANServer contains a remote denial-of-service issue. The
POST /game/cloud/getFileURL endpoint fails to limit the request body size or the number of elements in the attacker-controlled names JSON array. The server allocates response storage based directly on the length of this array using the make() function. Because the default configuration disables authentication, an unauthenticated remote client can obtain a session and send a crafted request that forces excessive memory allocation. This can lead to memory amplification, causing the server process to hang or be terminated by the kernel OOM (Out of Memory) killer, which disconnects all active players and makes the service unavailable until it is restarted.Recommendations
Update ageLANServer to version 1.15.2.
As a temporary mitigation, enable authentication in the server configuration to prevent unauthenticated clients from accessing the vulnerable endpoint.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agelanserver