Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4595-rvpx-4q34 | emp3r0r has an unauthenticated HTTP Polling DoS |
Tue, 15 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing. Version 4.2.5 patches the issue. | |
| Title | emp3r0r has an unauthenticated HTTP Polling DoS | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T20:48:05.156Z
Reserved: 2026-07-10T16:48:39.923Z
Link: CVE-2026-61554
No data.
Status : Received
Published: 2026-09-15T21:16:41.223
Modified: 2026-09-15T21:16:41.223
Link: CVE-2026-61554
No data.
OpenCVE Enrichment
No data.
-
CWE-400
Uncontrolled Resource Consumption
Github GHSA