CVE-2026-81535
Received Received - Intake

wolfSSH Unauthorized Forwarded-TCPIP Channel Buffer Overflow

Vulnerability report for CVE-2026-81535, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: wolfSSL Inc.

Description

In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wolfSSL Inc. wolfSSH 1.4.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in wolfSSH through 1.5.0 allows unauthorized forwarding of TCP/IP channels. When built with --enable-fwd, the system fails to properly validate forwarded-tcpip channel opens, letting malicious peers create unbounded per-channel buffers without authorization checks. Clients also don't verify forwarded-tcpip opens against registered forwards as required by RFC 4254 section 7.2.

Detection Guidance

Check if your wolfSSH version is 1.5.0 or earlier. Run 'wolfssh --version' to verify. Inspect SSH logs for unauthorized forwarded-tcpip channel opens or mismatches between client forwards and server responses. Use network monitoring tools to detect unexpected TCP forwarding attempts.

Impact Analysis

An attacker could exploit this to make the system allocate excessive memory for unauthorized forwarding channels, potentially causing denial-of-service or resource exhaustion. It may also allow unauthorized network access through improperly validated forwarding requests.

Mitigation Strategies

Upgrade wolfSSH to a patched version. Disable --enable-fwd if not needed. Implement strict validation for forwarded-tcpip channels. Ensure client-server forward matches are enforced per RFC 4254 section 7.2. Monitor logs for unauthorized forwarding attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81535. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart