OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-61554: emp3r0r has an unauthenticated HTTP Polling DoS

GitHub Advisories · officialPublished Sep 15, 2026Risk 37/100

### Summary The `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing. ### Details The plain HTTP C2 server starts the HTTP polling listener and forwards requests into `HandleHTTPServerSession`: ```go // core/internal/cc/server/c2_http_server.go mux.HandleFunc(c2Path, func(w http.ResponseWriter, req *http.Request) { stream, err := transport.HandleHTTPServerSession(w, req, &live.RuntimeConfig.MalleableC2) ... if stream != nil { go cborStreamAccept(transport.NewStreamTransport(stream, req.RemoteAddr)) } }) ``` The HTTP polling handler accepts an attacker-supplied `sessionID` and `init=1` cookie, then creates and stores a server-side stream before authentication: ```go // core/internal/transport/c2channel_http.go if isInit { stream = newHTTPServerStream(sessionID) w.WriteHeader(http.StatusOK) return stream, nil } ``` POST bodies for that unauthenticated session are read and queued before CBOR authentication rejects them: ```go // core/internal/transport/c2channel_http.go case http.MethodPost: data, err := io.ReadAll(req.Body) if err == nil && len(data) > 0 { select { case stream.readCh <- data: w.WriteHeader(http.StatusOK) ... } } ``` Authentication only happens later in the C2 dispatch layer: ```go // core/internal/cc/server/dispatcher.go secureConn := transport.NewSecureConn(t) ... n, err := secureConn.Read(authFrame) ``` ### PoC 1. Start the C2 server in a lab environment with the HTTP polling transport exposed, for example with `--http-port 12345`. 2. Send an unauthenticated HTTP POST to the default polling path `/api/v1/telemetry` with a random `sessionID` cookie and the `init=1` cookie value. 3. Send a second unauthenticated HTTP POST to `/api/v1/telemetry` using the same `sessionID`, with a request body containing repeated `A` bytes. 4. Observe that both unauthenticated requests return HTTP `200`. 5. Observe the C2 server log showing attacker-controlled bytes reaching the encrypted C2 frame parser, for example: `read: invalid encrypted chunk length: 1094795585`. 6. `1094795585` is `0x41414141`, which corresponds to `AAAA`, confirming unauthenticated request body data reached `cborProtocolDispatch` before CBOR `MsgAuth` authentication. 7. Repeat the request sequence concurrently to increase server resource usage and log volume. ### Impact - Remote unauthenticated attackers can create arbitrary HTTP polling sessions. - Attacker-controlled request bodies reach pre-auth C2 dispatch handling. - Repeated requests can consume server memory, goroutines, request handling capacity, and log volume. - C2 service availability and operator reliability may be degraded under sustained traffic. ### Remediation - Require authentication before creating long-lived HTTP polling sessions. - Do not forward request bodies into the C2 stream before validation. - Add strict request body limits.

Upgrade affected packages to a patched version: github.com/jm33-m0/emp3r0r/core 0.0.0-20260531142011-aed3d81641ab.

Vendor
Not specified
Product
github.com/jm33-m0/emp3r0r/core
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source