CVE-2025-34469

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound HTTP requests to attacker-supplied destinations. Because no outbound request rate limiting was enforced, unauthenticated remote attackers could repeatedly invoke these commands to generate unbounded HTTP traffic toward arbitrary third-party targets, allowing the Cowrie honeypot to be abused as a denial-of-service amplification node and masking the attacker’s true source address behind the honeypot’s IP.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cowrie:cowrie:*:*:*:*:*:*:*:*

History

13 Jan 2026, 22:10

Type Values Removed Values Added
First Time Cowrie
Cowrie cowrie
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:cowrie:cowrie:*:*:*:*:*:*:*:*
References () https://github.com/advisories/GHSA-83jg-m2pm-4jxj - () https://github.com/advisories/GHSA-83jg-m2pm-4jxj - Exploit, Third Party Advisory
References () https://github.com/cowrie/cowrie/issues/2622 - () https://github.com/cowrie/cowrie/issues/2622 - Exploit, Issue Tracking
References () https://github.com/cowrie/cowrie/pull/2800 - () https://github.com/cowrie/cowrie/pull/2800 - Exploit, Issue Tracking, Patch
References () https://github.com/cowrie/cowrie/releases/tag/v2.9.0 - () https://github.com/cowrie/cowrie/releases/tag/v2.9.0 - Release Notes
References () https://www.vulncheck.com/advisories/cowrie-unrestricted-wget-curl-emulation-enables-ssrf-based-ddos-amplification - () https://www.vulncheck.com/advisories/cowrie-unrestricted-wget-curl-emulation-enables-ssrf-based-ddos-amplification - Third Party Advisory

02 Jan 2026, 15:15

Type Values Removed Values Added
References () https://github.com/advisories/GHSA-83jg-m2pm-4jxj - () https://github.com/advisories/GHSA-83jg-m2pm-4jxj -

31 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-31 22:15

Updated : 2026-01-13 22:10


NVD link : CVE-2025-34469

Mitre link : CVE-2025-34469

CVE.ORG link : CVE-2025-34469


JSON object : View

Products Affected

cowrie

  • cowrie
CWE
CWE-918

Server-Side Request Forgery (SSRF)