{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/emp3r0r--0.0.0-20260531142011-aed3d81641ab/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jm33-m0:emp3r0r:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-61554"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["emp3r0r (\u003c 0.0.0-20260531142011-aed3d81641ab)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["jm33-m0"],"content_html":"\u003cp\u003eThe emp3r0r Command and Control (C2) server is susceptible to an unauthenticated denial-of-service (DoS) vulnerability, tracked as CVE-2026-61554. The flaw exists within the \u003ccode\u003ehttp_poll\u003c/code\u003e transport mechanism, which improperly handles HTTP sessions by allowing them to be created and populated with data prior to performing CBOR \u003ccode\u003eMsgAuth\u003c/code\u003e authentication.\u003c/p\u003e\n\u003cp\u003eAn attacker can send unauthenticated HTTP POST requests to the C2 polling endpoint, providing an arbitrary \u003ccode\u003esessionID\u003c/code\u003e and \u003ccode\u003einit=1\u003c/code\u003e cookie. The server processes these requests and forwards the body data into the C2 dispatch path before any authentication checks occur. By sending repeated, crafted requests, an attacker can consume system resources, including memory, goroutines, and logging capacity, leading to a degradation or total loss of C2 service availability. This issue affects versions of the emp3r0r core package prior to 0.0.0-20260531142011-aed3d81641ab.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing emp3r0r C2 server exposing the HTTP polling port.\u003c/li\u003e\n\u003cli\u003eAttacker sends an initial HTTP POST request to the C2 endpoint (e.g., \u003ccode\u003e/api/v1/telemetry\u003c/code\u003e) with \u003ccode\u003einit=1\u003c/code\u003e and a chosen \u003ccode\u003esessionID\u003c/code\u003e cookie.\u003c/li\u003e\n\u003cli\u003eServer-side code calls \u003ccode\u003enewHTTPServerStream\u003c/code\u003e, creating and storing an unauthenticated stream object.\u003c/li\u003e\n\u003cli\u003eAttacker sends subsequent HTTP POST requests to the same endpoint using the established \u003ccode\u003esessionID\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe server invokes \u003ccode\u003eio.ReadAll(req.Body)\u003c/code\u003e on the unauthenticated session and queues the data into the internal \u003ccode\u003estream.readCh\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker-controlled data is forwarded into the C2 dispatch layer before the CBOR authentication process is reached.\u003c/li\u003e\n\u003cli\u003eAttacker repeats the request cycle to maximize resource consumption, triggering a server DoS.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the degradation of C2 infrastructure availability. By forcing the server to process and queue unauthenticated request bodies, an attacker can exhaust server-side resources, including goroutines and memory. This is particularly impactful for threat actors relying on the integrity and uptime of their C2 infrastructure for post-exploitation operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all internet-facing emp3r0r C2 instances to version 0.0.0-20260531142011-aed3d81641ab or later. If patching is not immediately feasible, restrict access to the HTTP polling endpoint using network-level controls such as firewalls or VPNs to ensure only authorized traffic can reach the listener.\u003c/p\u003e\n","date_modified":"2026-09-16T01:05:21Z","date_published":"2026-09-16T01:05:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-emp3r0r-dos/","summary":"An unauthenticated remote denial-of-service vulnerability in the emp3r0r C2 server (CVE-2026-61554) allows attackers to exhaust server resources by injecting arbitrary request bodies before session authentication.","title":"Unauthenticated Denial of Service in emp3r0r HTTP Polling Transport","url":"https://feed.craftedsignal.io/briefs/2026-09-emp3r0r-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Emp3r0r (\u003c 0.0.0-20260531142011-Aed3d81641ab)","version":"https://jsonfeed.org/version/1.1"}