Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass
A specially crafted nonce routes unauthenticated requests through the NoEncoder path, where startSessionHandler() reads the entire request body without limits, allowing attacker-driven memory exhaustion and process crash.