Tunnel Bypass Vulnerability in Chisel TCP/UDP Tunnel
CVE-2026-48113

8.5HIGH

Key Information:

Vendor

Jpillora

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-48113?

The Chisel application, a tool for creating TCP and UDP tunnels over HTTP secured via SSH, has a vulnerability that allows authenticated clients to bypass Access Control List (ACL) restrictions defined in the --authfile. In versions prior to 1.11.5, the ACL enforcement occurs only during the initial handshake and does not apply to subsequent SSH channels used to transmit traffic. This flaw enables an authenticated malicious client to connect to a permitted remote server, allowing them to establish channels to any host and port accessible from the server, potentially leading to unauthorized data access and exfiltration.

Affected Version(s)

chisel < 1.11.5

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.