Description
In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.
Published: 2026-10-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Wolfssl
Wolfssl wolfssh
Vendors & Products Wolfssl
Wolfssl wolfssh

Wed, 07 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.
Title wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check
Weaknesses CWE-862
CWE-863
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published:

Updated: 2026-10-07T18:37:36.186Z

Reserved: 2026-08-26T23:09:37.634Z

Link: CVE-2026-81535

cve-icon Vulnrichment

Updated: 2026-10-07T18:37:30.970Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-10-07T03:16:59.567

Modified: 2026-10-07T19:17:44.487

Link: CVE-2026-81535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:45:10Z

Weaknesses