🔐 CVE Alert

CVE-2026-81535

UNKNOWN 0.0

wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.

CWE CWE-862 CWE-863
Vendor wolfssl inc.
Product wolfssh
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for wolfssl inc. wolfssh

Be the first to know when new unknown vulnerabilities affecting wolfssl inc. wolfssh are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

wolfSSL Inc. / wolfSSH
1.4.8 ≤ 1.5.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/wolfSSL/wolfssh/commit/616eb681e70759c30c3ba158f2b18d7bd954def8 github.com: https://github.com/wolfSSL/wolfssh/commit/e396a0a4b6b367f10270287446a4be0071742b5c github.com: https://github.com/wolfSSL/wolfssh/commit/79a7f299337a28aa561409688a268d0efe6e295c

Credits

zhangph (GitHub afldl)