{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/age-of-empires/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ageLANServer"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","memory-exhaustion","json-injection","age-of-empires"],"_cs_type":"advisory","_cs_vendors":["luskaner"],"content_html":"\u003cp\u003eThe ageLANServer application, specifically the \u003ccode\u003ePOST /game/cloud/getFileURL\u003c/code\u003e endpoint, contains a critical vulnerability due to unbounded memory allocation based on attacker-supplied input. When the server processes the \u003ccode\u003enames\u003c/code\u003e JSON array, it performs a slice allocation using \u003ccode\u003emake(i.A, len(req.Names.Data))\u003c/code\u003e without enforcing any bounds on the array length or the HTTP request body size. By default, the application ships with \u003ccode\u003eAuthentication = 'disabled'\u003c/code\u003e, allowing any network-reachable client to obtain a valid session identifier through the \u003ccode\u003eplatformlogin\u003c/code\u003e flow without credentials.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by sending a specially crafted request containing a large number of elements in the \u003ccode\u003enames\u003c/code\u003e array, forcing the server to allocate memory proportional to the input. This behavior leads to massive memory amplification, effectively triggering the kernel OOM killer and crashing the server process. The vulnerability affects unmodified installations of the software as shipped in its default configuration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing ageLANServer deployment.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a POST request to \u003ccode\u003e/game/login/platformlogin\u003c/code\u003e with arbitrary \u003ccode\u003eaccountType\u003c/code\u003e and \u003ccode\u003eplatformUserID\u003c/code\u003e parameters to obtain a \u003ccode\u003esessionID\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a malicious JSON payload with an oversized \u003ccode\u003enames\u003c/code\u003e array (e.g., millions of elements) encapsulated within a JSON string to bypass initial schema parsers.\u003c/li\u003e\n\u003cli\u003eThe attacker sends the crafted payload in a \u003ccode\u003ePOST /game/cloud/getFileURL?sessionID=\u0026lt;id\u0026gt;\u003c/code\u003e request to the server.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eBind()\u003c/code\u003e function in \u003ccode\u003eserver/internal/http.go\u003c/code\u003e parses the large request body into the \u003ccode\u003egetFileURLRequest\u003c/code\u003e struct without limiting the size of the input.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eGetFileURL\u003c/code\u003e handler in \u003ccode\u003eserver/internal/routes/game/cloud/getFileURL.go\u003c/code\u003e extracts the length of the \u003ccode\u003enames\u003c/code\u003e array.\u003c/li\u003e\n\u003cli\u003eThe application invokes \u003ccode\u003emake()\u003c/code\u003e using the attacker-controlled length, leading to immediate massive memory allocation.\u003c/li\u003e\n\u003cli\u003eThe system memory is exhausted, triggering the kernel OOM killer and resulting in a service crash (Denial of Service).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a full process crash, rendering the game server unavailable to all legitimate players. Because the vulnerability is pre-authentication, no game ownership or valid credentials are required. Dynamic testing confirmed that concurrent requests can force OOM-killer termination of the process, ensuring consistent service disruption. This affects any environment where the server is exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following remediation and detection actions to mitigate this risk:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply input validation logic in \u003ccode\u003eserver/internal/routes/game/cloud/getFileURL.go\u003c/code\u003e to enforce a hard cap on \u003ccode\u003elen(req.Names.Data)\u003c/code\u003e before memory allocation.\u003c/li\u003e\n\u003cli\u003eImplement middleware using \u003ccode\u003ehttp.MaxBytesReader\u003c/code\u003e to limit the size of incoming HTTP request bodies across all endpoints.\u003c/li\u003e\n\u003cli\u003eDisable the \u003ccode\u003eAuthentication = 'disabled'\u003c/code\u003e setting in \u003ccode\u003eserver/resources/config/config.toml\u003c/code\u003e to enforce mandatory session verification against real platform providers.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for anomalous POST request sizes or high-frequency login activity indicating automated reconnaissance.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T21:25:30Z","date_published":"2026-10-09T21:25:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-agelanserver-dos/","summary":"An unauthenticated remote denial-of-service vulnerability in ageLANServer allows attackers to trigger excessive memory consumption by sending crafted JSON arrays to the getFileURL endpoint.","title":"Unbounded JSON Array Allocation in ageLANServer Leads to Remote DoS","url":"https://feed.craftedsignal.io/briefs/2026-10-agelanserver-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Age-of-Empires","version":"https://jsonfeed.org/version/1.1"}