Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-81535— wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check

Quick assessment

Affected
wolfSSL Inc. wolfSSH
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 wolfSSH 1.5.0 版本(通过启用 编译选项构建)中, 文件中的 函数仅对 类型的通道打开操作施加了转发策略回调检查。然而,对于 类型的通道打开操作,却未进行任何授权检查,且对其数量没有上限限制。这使得恶意的 SSH 对端能够强制本端为应用程序从未授权批准的转发通道分配无限制的每通道缓冲区。此外,客户端也未按照 RFC 4254 第 7.2 节的要求,将 通道打开请求与其先前通过 请求注册的转发信息进行比对校验。因此,恶意的 SSH 服务端可以为客户端从未要求转发的地址和端口擅自打开通道转发。

CVSS 6.3 · Medium

Possible ATT&CK Techniques 2 AI

T1090 · Proxy T1571 · Non-Standard Port
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81535

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check
Source: CVE Program / CVE List V5
Vulnerability Description
In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL Inc. wolfSSH 1.4.8 ~ 1.5.0 -

II. Public POCs for CVE-2026-81535

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81535

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-81535 (2)

Same Patch Batch · wolfSSL Inc. · 2026-10-07 · 4 CVEs total

CVE-2026-16516 9.0 CRITICAL wolfSSH ECDSA host key curve not validated against negotiated algorithm
CVE-2026-84897 6.9 MEDIUM wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated
CVE-2026-83742 5.3 MEDIUM wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-

IV. Related Vulnerabilities

V. Comments for CVE-2026-81535

No comments yet


Leave a comment