Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfssh |
|
| Vendors & Products |
Wolfssl
Wolfssl wolfssh |
Wed, 07 Oct 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward. | |
| Title | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check | |
| Weaknesses | CWE-862 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2026-10-07T18:37:36.186Z
Reserved: 2026-08-26T23:09:37.634Z
Link: CVE-2026-81535
Updated: 2026-10-07T18:37:30.970Z
Status : Undergoing Analysis
Published: 2026-10-07T03:16:59.567
Modified: 2026-10-07T19:17:44.487
Link: CVE-2026-81535
No data.
OpenCVE Enrichment
Updated: 2026-10-07T03:45:10Z