CVE-2025-34469: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-34469 is a Server-Side Request Forgery (SSRF) vulnerability in the Cowrie SSH/Telnet honeypot's emulated shell implementation of wget and curl commands. In the default emulated shell configuration, these command emulations perform real outbound HTTP requests to attacker-supplied destinations without any rate limiting, allowing unauthenticated remote attackers to abuse the honeypot as a DDoS amplification node while masking their true source IP behind the honeypot's address. All Cowrie versions prior to 2.9.0 are affected. The vulnerability was publicly disclosed on December 31, 2025, and carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from Cowrie's design decision to have its wget and curl command emulations execute real outbound HTTP requests — a feature intended to capture malware samples for later analysis. Because no rate limiting or request throttling was enforced on these emulated commands, an attacker connecting via SSH or Telnet could issue an unbounded number of wget or curl commands targeting arbitrary third-party hosts. The attack requires no special privileges; any credentials accepted by the honeypot (including default or brute-forced ones) are sufficient. A public proof-of-concept is included in the security advisory, demonstrating that chaining 100 wget commands per SSH session and repeating the session 10 times yields 1,000 HTTP requests to a victim host within approximately 5 seconds (GitHub Advisory, GitHub Issue).

Impact

Successful exploitation allows attackers to weaponize Cowrie honeypot deployments as unwitting DDoS amplification nodes, directing unbounded HTTP traffic at arbitrary third-party targets while the honeypot's IP appears as the sole source in victim logs. There is no confidentiality or integrity impact on the honeypot itself; the primary harm is availability impact on third-party victims and consumption of the honeypot host's network resources. Honeypot operators may face abuse complaints, infrastructure blocklisting, or upstream bandwidth exhaustion as a secondary consequence (GitHub Advisory).

Exploitability

This vulnerability has been observed being actively exploited in the wild prior to the patch, with a community member reporting sustained automated abuse attempts beginning in July 2025 — months before formal disclosure (GitHub Issue). A detailed proof-of-concept is publicly available in the official security advisory (GitHub Advisory). The EPSS score is approximately 0.00135, reflecting low predicted exploitation probability in the broader ecosystem, though in-the-wild abuse has already been confirmed. No specific threat actor attribution is available, and the vulnerability is not currently listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cowrie honeypot instances running versions prior to 2.9.0, typically listening on TCP port 22 (SSH) or 23 (Telnet). Cowrie honeypots often accept common default or weak credentials.
  2. Authentication: Connect via SSH using a brute-forced or default credential pair (e.g., root/adidas1, test/test) that Cowrie is configured to accept: sshpass -p <password> ssh <user>@<honeypot-ip>.
  3. Craft amplification payload: Build a payload consisting of many repeated wget or curl commands targeting the victim host: PAYLOAD=$(for i in {1..100}; do echo -n 'wget -q http://<victim-ip>;'; done).
  4. Execute payload: Run the payload over SSH, repeating the session multiple times to multiply the request volume: for i in {1..10}; do sshpass -p <password> ssh <user>@<honeypot-ip> "$PAYLOAD"; done.
  5. Observe amplification: The victim's HTTP server receives 1,000+ requests originating exclusively from the honeypot's IP address, with the attacker's IP never appearing in victim logs, effectively masking the attacker's identity (GitHub Advisory).

Indicators of compromise

  • Network (Honeypot): High volume of outbound HTTP/HTTPS GET requests from the Cowrie host to external IPs or domains, particularly in rapid succession; unusual egress bandwidth spikes from the honeypot server.
  • Logs (Cowrie JSON log cowrie.json): Large numbers of cowrie.command.input events containing repeated wget or curl commands targeting the same external URL within a single session; cowrie.session.file_download or cowrie.session.file_download.failed events for non-malware URLs (e.g., web pages rather than binaries).
  • Logs (Cowrie JSON log cowrie.json): Sessions from a single source IP issuing hundreds of network command invocations; cowrie.login.success events followed immediately by bulk command execution.
  • Network (Victim-side): Repeated HTTP GET requests from the honeypot's IP address in victim web server access logs, with no corresponding attacker IP visible (GitHub Issue, GitHub Advisory).

Mitigation and workarounds

Upgrade Cowrie to version 2.9.0 or later, which introduces a rate limiting mechanism (default: 5 requests per 60 seconds per host) for outbound requests in wget and curl emulations via PR #2800 (Cowrie v2.9.0 Release, GitHub PR #2800). As a temporary workaround for operators unable to upgrade immediately, disabling the wget and curl command emulations in the Cowrie configuration will prevent exploitation, though this reduces malware sample collection capability. Rate limiting parameters (wget_rate_limit_enabled, wget_rate_limit_requests, wget_rate_limit_window, wget_rate_limit_max_hosts) are configurable via cowrie.cfg in version 2.9.0.

Community reactions

The vulnerability was investigated and responsibly disclosed by researchers Abraham Gebrehiwot and Filippo Lauria, with contributions from Michele Castellaneta, Claudio Porta, and Sara Afzal — all affiliated with the Institute of Informatics and Telematics (IIT) at the Italian National Research Council (CNR) (GitHub Advisory). A community member independently reported active exploitation in a GitHub issue in July 2025, noting sustained automated abuse attempts against their Cowrie deployment and requesting a rate-limiting solution (GitHub Issue). The Cowrie maintainer (Michel Oosterhof) promptly merged the fix in November 2025 and released version 2.9.0, acknowledging the issue's significance.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management