๐Ÿ” CVE Alert

CVE-2026-61554

HIGH 7.5

emp3r0r has an unauthenticated HTTP Polling DoS

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing. Version 4.2.5 patches the issue.

CWE CWE-400
Vendor jm33-m0
Product emp3r0r
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for jm33-m0 emp3r0r

Be the first to know when new high vulnerabilities affecting jm33-m0 emp3r0r are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

jm33-m0 / emp3r0r
< 4.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34 github.com: https://github.com/jm33-m0/emp3r0r/releases/tag/v4.2.5