Hi there,
i checked the latest TS3-Server Download changelog, but there is no current update notice in there.
What is the purpose/change inside this Build?
Hey,
Unfortunately, the entry got a little lost in the changelog and is buried at the very bottom of the changelog for both the latest TS3 Server and TS3 Client versions, sorry about that!
Here’s the changelog:
=== Server Release 3.13.8 27 May 2026
! Server: CVE-2026-4390
Use-After-Free via Inconsistent Connection State Management Leading to Denial-of-Service:
A vulnerability in connection state handling could allow authenticated remote attackers
to trigger denial-of-service conditions, potentially resulting in service instability
or server restarts.
! Server CVE-2026-4391
Finding Heap-Based Buffer Overflow in ECC Key Parsing Leading to Denial-of-Service
! Server: CVE-2026-4392
Assertion Failure Triggered by Crafted Input Leading to Denial-of-Service:
A vulnerability in input validation could allow unauthenticated remote attackers to
trigger denial-of-service conditions, including service instability or server restarts.
2 Likes
Hi and thank you for the answer.
Well, indeed I didn’t scrolled down, because of the expected structure of this document.
Changelog should be corrected and downloadfile should be reuploaded.
Best regards from Germany