GHSA-4595-rvpx-4q34: High severity go/github.com/jm33-m0/emp3r0r/core vulnerability

Published Sep 15, 2026
·
Updated

Summary The httppoll C2 transport accepts attacker-controlled HTTP polling sessions before CBOR MsgAuth authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and trigger pre-auth C2 processing.

Details The plain HTTP C2 server starts the HTTP polling listener and forwards requests into HandleHTTPServerSession: go // core/internal/cc/server/c2httpserver.go mux.HandleFunc(c2Path, func(w http.ResponseWriter, req http.Request) { stream, err := transport.HandleHTTPServerSession(w, req, &live.RuntimeConfig.MalleableC2) ... if stream != nil { go cborStreamAccept(transport.NewStreamTransport(stream, req.RemoteAddr)) } }) The HTTP polling handler accepts an attacker-supplied sessionID and init=1 cookie, then creates and stores a server-side stream before authentication:

go // core/internal/transport/c2channelhttp.go if isInit { stream = newHTTPServerStream(sessionID) w.WriteHeader(http.StatusOK) return stream, nil } POST bodies for that unauthenticated session are read and queued before CBOR authentication rejects them: go // core/internal/transport/c2channelhttp.go case http.MethodPost: data, err := io.ReadAll(req.Body) if err == nil && len(data) > 0 { select { case stream.readCh <- data: w.WriteHeader(http.StatusOK) ... } } Authentication only happens later in the C2 dispatch layer: go // core/internal/cc/server/dispatcher.go secureConn := transport.NewSecureConn(t) ... n, err := secureConn.Read(authFrame)

PoC 1. Start the C2 server in a lab environment with the HTTP polling transport exposed, for example with --http-port 12345. 2. Send an unauthenticated HTTP POST to the default polling path /api/v1/telemetry with a random sessionID cookie and the init=1 cookie value. 3. Send a second unauthenticated HTTP POST to /api/v1/telemetry using the same sessionID, with a request body containing repeated A bytes. 4. Observe that both unauthenticated requests return HTTP 200. 5. Observe the C2 server log showing attacker-controlled bytes reaching the encrypted C2 frame parser, for example: read: invalid encrypted chunk length: 1094795585. 6. 1094795585 is 0x41414141, which corresponds to AAAA, confirming unauthenticated request body data reached cborProtocolDispatch before CBOR MsgAuth authentication. 7. Repeat the request sequence concurrently to increase server resource usage and log volume.

Impact - Remote unauthenticated attackers can create arbitrary HTTP polling sessions. - Attacker-controlled request bodies reach pre-auth C2 dispatch handling. - Repeated requests can consume server memory, goroutines, request handling capacity, and log volume. - C2 service availability and operator reliability may be degraded under sustained traffic.

Remediation - Require authentication before creating long-lived HTTP polling sessions. - Do not forward request bodies into the C2 stream before validation. - Add strict request body limits.

Affected Software

1 affected componentFixes available
go/github.com/jm33-m0/emp3r0r/core<0.0.0-20260531142011-aed3d81641ab
0.0.0-20260531142011-aed3d81641ab

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/jm33-m0/emp3r0r/core to a version that resolves this vulnerability.

    Fixed in 0.0.0-20260531142011-aed3d81641ab
  2. Configuration

    Do not forward request bodies into the C2 dispatch path before CBOR `MsgAuth` authentication is completed. Ensure pre-auth HTTP polling requests do not reach `cborProtocolDispatch` / `cborStreamAccept` (where attacker-controlled bytes are parsed) before authentication.

    C2 HTTP polling handler (core/internal/cc/server/c2_http_server.go / dispatcher.go / core/internal/transport/c2channel_http.go) Request body handling / forwarding to dispatch = Validate/limit request bodies before forwarding into the C2 dispatch path; do not forward pre-auth request bodies into cborProtocolDispatch
  3. Configuration

    Add strict request body limits so POST bodies for unauthenticated polling sessions cannot consume excessive server memory/goroutines and cannot reach pre-auth C2 processing.

    C2 HTTP polling transport Strict request body limits = Add strict request body size limits (reject/stop reading oversized bodies)
  4. Configuration

    Require authentication before creating and storing long-lived HTTP polling sessions/streams. Ensure the HTTP polling transport does not accept attacker-controlled `sessionID` and `init=1` to create server-side streams before CBOR `MsgAuth` authentication is completed.

    C2 HTTP polling session creation Authentication requirement for long-lived HTTP polling sessions = Require authentication before creating/storing server-side polling streams (before accepting attacker-controlled `sessionID`/`init=1`)

Event History

Sep 15, 2026
Advisory Published
via GitHub·08:47 PM
Data Sourced
via GitHub·08:47 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments running the plain HTTP C2 server with the HTTP polling listener reachable by an attacker are exposed. The affected component is the http_poll C2 transport in go/github.com/jm33-m0/emp3r0r/core.

2

Does exploitation require credentials or prior authentication?

No. A remote attacker can supply a polling session ID and an init=1 cookie to create a server-side stream before CBOR MsgAuth authentication completes.

3

What can an unauthenticated attacker cause?

They can create arbitrary polling sessions and submit request bodies that are queued and forwarded into the C2 dispatch path before authentication. This can consume server resources and trigger pre-auth C2 processing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203