CVE-2026-81535

Summary

In wolfSSH through 1.5.0 built with –enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.

Affected Software

VendorProductVersion RangeStatus
wolfSSL Inc.wolfSSH1.4.8 <= 1.5.0affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization
  • CWE-863: CWE-863 Incorrect Authorization

References