PatchSiren

TeamSpeak CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM TeamSpeak CVE published 2026-05-27

CVE-2026-4392

A reachable assertion vulnerability exists in TeamSpeak 3 Server versions up to and including 3.13.7. The flaw resides in the clientek handshake handler, where manipulation of the `proof` argument can trigger an assertion failure. This vulnerability is remotely exploitable without authentication. The issue has been resolved in version 3.13.8.

MEDIUM TeamSpeak CVE published 2026-05-27

CVE-2026-4391

A heap-based buffer overflow vulnerability exists in TeamSpeak 3 Server versions up to and including 3.13.7. The flaw resides in the ECC Key Parser component, where improper handling of input data can lead to memory corruption. The vulnerability is remotely exploitable without authentication, presenting a moderate risk to server availability. TeamSpeak has addressed this issue in version 3.13.8, which sho [truncated]

MEDIUM TeamSpeak CVE published 2026-05-27

CVE-2026-4390

A use-after-free vulnerability exists in TeamSpeak 3 Server versions up to and including 3.13.7. The flaw resides in the `process_resend_queue` function within the Connection State Management component. Remote attackers can trigger this memory safety issue, potentially leading to denial of service or limited integrity/availability impacts. The vulnerability is remotely exploitable without user interaction [truncated]