Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfssh |
|
| Vendors & Products |
Wolfssl
Wolfssl wolfssh |
Wed, 07 Oct 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward. | |
| Title | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check | |
| Weaknesses | CWE-862 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2026-10-07T02:39:27.830Z
Reserved: 2026-08-26T23:09:37.634Z
Link: CVE-2026-81535
No data.
Status : Received
Published: 2026-10-07T03:16:59.567
Modified: 2026-10-07T03:16:59.567
Link: CVE-2026-81535
No data.
OpenCVE Enrichment
Updated: 2026-10-07T03:45:10Z