Weakness in frp's SSH Tunnel Gateway Allows Unauthenticated Access
CVE-2026-73564

8.7HIGH

Key Information:

Vendor

Fatedier

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73564?

The SSH Tunnel Gateway in the frp proxy service is vulnerable to an improper input validation flaw. Specifically, an attacker can exploit this vulnerability by sending a malformed SSH exec channel request. The attack manipulates the length of the payload, bypassing the expected bounds checks. As a result, this could lead to a panic in the TunnelServer, causing it to crash and terminate all active tunnels used by legitimate users. Mitigation is available in version 0.70.1, which addresses this input validation issue effectively.

Affected Version(s)

frp >= 0.53.0, < 0.70.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.