Threat Advisory

emp3r0r HTTP Polling Flaw Consumes Server Resources

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61554 with a CVSS score of 7.5 is a high severity vulnerability affecting github.com/jm33-m0/emp3r0r/core versions < 0.0.0-20260531142011-aed3d81641ab in the emp3r0r C2 transport, where an unauthenticated HTTP Polling DoS can be achieved by creating arbitrary polling sessions and sending request bodies that are forwarded into the C2 dispatch path before CBOR MsgAuth authentication is completed, consuming server resources and triggering pre-auth C2 processing. The plain HTTP C2 server starts the HTTP polling listener and forwards requests into HandleHTTPServerSession, accepting an attacker-supplied sessionID and init=1 cookie, then creates and stores a server-side stream before authentication. POST bodies for that unauthenticated session are read and queued before CBOR authentication rejects them, allowing remote unauthenticated attackers to create arbitrary HTTP polling sessions, consume server memory, goroutines, request handling capacity, and log volume, degrading C2 service availability and operator reliability under sustained traffic.

RECOMMENDATION:

We recommend you to update emp3r0r to version 0.0.0-20260531142011-aed3d81641ab.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61554 with a CVSS score of 7.5 is a high severity vulnerability affecting github.com/jm33-m0/emp3r0r/core versions < 0.0.0-20260531142011-aed3d81641ab in the emp3r0r C2 transport, where an unauthenticated HTTP Polling DoS can be achieved by creating arbitrary polling sessions and sending request bodies that are forwarded into the C2 dispatch path before CBOR MsgAuth authentication is completed, consuming server resources and triggering pre-auth C2 processing. The plain HTTP C2 server starts the HTTP polling listener and forwards requests into HandleHTTPServerSession, accepting an attacker-supplied sessionID and init=1 cookie, then creates and stores a server-side stream before authentication. POST bodies for that unauthenticated session are read and queued before CBOR authentication rejects them, allowing remote unauthenticated attackers to create arbitrary HTTP polling sessions, consume server memory, goroutines, request handling capacity, and log volume, degrading C2 service availability and operator reliability under sustained traffic.

RECOMMENDATION:

We recommend you to update emp3r0r to version 0.0.0-20260531142011-aed3d81641ab.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu