Tunnel Bypass Vulnerability in Chisel TCP/UDP Tunnel
CVE-2026-48113
8.5HIGH
What is CVE-2026-48113?
The Chisel application, a tool for creating TCP and UDP tunnels over HTTP secured via SSH, has a vulnerability that allows authenticated clients to bypass Access Control List (ACL) restrictions defined in the --authfile. In versions prior to 1.11.5, the ACL enforcement occurs only during the initial handshake and does not apply to subsequent SSH channels used to transmit traffic. This flaw enables an authenticated malicious client to connect to a permitted remote server, allowing them to establish channels to any host and port accessible from the server, potentially leading to unauthorized data access and exfiltration.
Affected Version(s)
chisel < 1.11.5
