
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34469 is a Server-Side Request Forgery (SSRF) vulnerability in the Cowrie SSH/Telnet honeypot's emulated shell implementation of wget and curl commands. In the default emulated shell configuration, these command emulations perform real outbound HTTP requests to attacker-supplied destinations without any rate limiting, allowing unauthenticated remote attackers to abuse the honeypot as a DDoS amplification node while masking their true source IP behind the honeypot's address. All Cowrie versions prior to 2.9.0 are affected. The vulnerability was publicly disclosed on December 31, 2025, and carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from Cowrie's design decision to have its wget and curl command emulations execute real outbound HTTP requests — a feature intended to capture malware samples for later analysis. Because no rate limiting or request throttling was enforced on these emulated commands, an attacker connecting via SSH or Telnet could issue an unbounded number of wget or curl commands targeting arbitrary third-party hosts. The attack requires no special privileges; any credentials accepted by the honeypot (including default or brute-forced ones) are sufficient. A public proof-of-concept is included in the security advisory, demonstrating that chaining 100 wget commands per SSH session and repeating the session 10 times yields 1,000 HTTP requests to a victim host within approximately 5 seconds (GitHub Advisory, GitHub Issue).
Successful exploitation allows attackers to weaponize Cowrie honeypot deployments as unwitting DDoS amplification nodes, directing unbounded HTTP traffic at arbitrary third-party targets while the honeypot's IP appears as the sole source in victim logs. There is no confidentiality or integrity impact on the honeypot itself; the primary harm is availability impact on third-party victims and consumption of the honeypot host's network resources. Honeypot operators may face abuse complaints, infrastructure blocklisting, or upstream bandwidth exhaustion as a secondary consequence (GitHub Advisory).
This vulnerability has been observed being actively exploited in the wild prior to the patch, with a community member reporting sustained automated abuse attempts beginning in July 2025 — months before formal disclosure (GitHub Issue). A detailed proof-of-concept is publicly available in the official security advisory (GitHub Advisory). The EPSS score is approximately 0.00135, reflecting low predicted exploitation probability in the broader ecosystem, though in-the-wild abuse has already been confirmed. No specific threat actor attribution is available, and the vulnerability is not currently listed in the CISA KEV catalog.
root/adidas1, test/test) that Cowrie is configured to accept: sshpass -p <password> ssh <user>@<honeypot-ip>.wget or curl commands targeting the victim host: PAYLOAD=$(for i in {1..100}; do echo -n 'wget -q http://<victim-ip>;'; done).for i in {1..10}; do sshpass -p <password> ssh <user>@<honeypot-ip> "$PAYLOAD"; done.cowrie.json): Large numbers of cowrie.command.input events containing repeated wget or curl commands targeting the same external URL within a single session; cowrie.session.file_download or cowrie.session.file_download.failed events for non-malware URLs (e.g., web pages rather than binaries).cowrie.json): Sessions from a single source IP issuing hundreds of network command invocations; cowrie.login.success events followed immediately by bulk command execution.Upgrade Cowrie to version 2.9.0 or later, which introduces a rate limiting mechanism (default: 5 requests per 60 seconds per host) for outbound requests in wget and curl emulations via PR #2800 (Cowrie v2.9.0 Release, GitHub PR #2800). As a temporary workaround for operators unable to upgrade immediately, disabling the wget and curl command emulations in the Cowrie configuration will prevent exploitation, though this reduces malware sample collection capability. Rate limiting parameters (wget_rate_limit_enabled, wget_rate_limit_requests, wget_rate_limit_window, wget_rate_limit_max_hosts) are configurable via cowrie.cfg in version 2.9.0.
The vulnerability was investigated and responsibly disclosed by researchers Abraham Gebrehiwot and Filippo Lauria, with contributions from Michele Castellaneta, Claudio Porta, and Sara Afzal — all affiliated with the Institute of Informatics and Telematics (IIT) at the Italian National Research Council (CNR) (GitHub Advisory). A community member independently reported active exploitation in a GitHub issue in July 2025, noting sustained automated abuse attempts against their Cowrie deployment and requesting a rate-limiting solution (GitHub Issue). The Cowrie maintainer (Michel Oosterhof) promptly merged the fix in November 2025 and released version 2.9.0, acknowledging the issue's significance.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."