Description
emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing. Version 4.2.5 patches the issue.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

emp3r0r is a Linux‑based C2 tool that uses an HTTP polling transport. Prior to version 4.2.5, the server accepts polling sessions before completing CBOR MsgAuth authentication. An unauthenticated attacker can create arbitrary sessions and send request bodies that are forwarded to the C2 dispatch path, consuming server resources and triggering pre‑authentication processing. This results in a Denial of Service. The weakness is resource exhaustion (CWE‑400).

Affected Systems

Emp3r0r C2 tool released by jm33‑m0. Versions prior to 4.2.5 are vulnerable. Version 4.2.5 and later contain the fix.

Risk and Exploitability

The CVSS score is 7.5, indicating a high‑severity vulnerability. The EPSS score is less than 1%, showing a low probability of exploitation in the current environment, and the issue is not listed in CISA KEV. An attacker can exploit the flaw remotely through unauthenticated HTTP traffic; no special privileges or pre‑existing access are required. Once an HTTP session is established, the attacker can flood the server with request bodies, exhausting CPU or memory and preventing legitimate clients from connecting.

Generated by OpenCVE AI on September 18, 2026 at 13:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Emp3r0r to version 4.2.5 or later, which implements authentication before polling sessions are accepted.
  • If an upgrade cannot be performed immediately, configure the web server or firewall to rate‑limit or block HTTP polling requests from untrusted addresses, or temporarily disable the polling transport in the configuration to prevent unauthorized sessions.
  • Monitor the C2 server for unusual resource consumption, and consider isolating the process from critical services or applying process limits to mitigate denial of service impact.

Generated by OpenCVE AI on September 18, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4595-rvpx-4q34 emp3r0r has an unauthenticated HTTP Polling DoS
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jm33-m0
Jm33-m0 emp3r0r
Vendors & Products Jm33-m0
Jm33-m0 emp3r0r

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing. Version 4.2.5 patches the issue.
Title emp3r0r has an unauthenticated HTTP Polling DoS
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:59:54.763Z

Reserved: 2026-07-10T16:48:39.923Z

Link: CVE-2026-61554

cve-icon Vulnrichment

Updated: 2026-09-16T17:59:46.663Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:41.223

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption