THREAT OPS › Threat News › [GHSA] GHSA-4595-rvpx-4q34 (high) — emp3r0r has an unauthenticated HTTP Polling DoS
[GHSA] GHSA-4595-rvpx-4q34 (high) — emp3r0r has an unauthenticated HTTP Polling DoS
GHSA-4595-rvpx-4q34 Severity: high CVE: CVE-2026-61554
emp3r0r has an unauthenticated HTTP Polling DoS
### Summary The `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can co
Indicators of compromise
- CVE-2026-61554cve
Original source: https://github.com/advisories/GHSA-4595-rvpx-4q34