Vulnerability in wolfSSH Affects Unauthenticated TCP/IP Forwarding Operations
CVE-2026-81535

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-81535?

A flaw in wolfSSH allows unauthorized forwarding of TCP/IP channels due to insufficient authorization checks on forwarded-tcpip opens. When built with the --enable-fwd option, the DoChannelOpen() function is improperly configured, leading to potential exploitation by malicious SSH peers. By bypassing established forwarding policies, a compromised server can allocate an unbounded number of per-channel buffers without client consent. This oversight not only jeopardizes the integrity of the SSH connection but also opens the door for unauthorized data routing to arbitrary destinations, presenting significant security risks.

Affected Version(s)

wolfSSH 1.4.8 <= 1.5.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zhangph (GitHub afldl)
.