CVE-2026-81535: wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check
In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
wolfSSH installations through version 1.5.0 are affected when built with the --enable-fwd option. The issue concerns the SSH client when it connects to a malicious or compromised SSH peer.
What does an attacker need to exploit this?
The attacker needs to control, or be able to act as, the SSH server or peer connected to by the wolfSSH client. That peer can send unsolicited forwarded-tcpip channel-open requests without having an authorized or registered forwarding request.
What is the practical impact of exploitation?
A malicious peer can cause the endpoint to allocate per-channel forwarding buffers for channels the application did not authorize. Because forwarded-tcpip opens are not capped in number, this can result in unbounded resource consumption and channels associated with unrequested addresses and ports.
Is a default build affected?
The vulnerable behavior is present only in builds that enable forwarding with --enable-fwd. The supplied information does not establish whether that option is enabled by default.
How can I determine whether my environment is affected?
Check whether wolfSSH is version 1.5.0 or earlier and whether it was built with --enable-fwd. Review client connections to untrusted SSH servers, especially for unexpected forwarded-tcpip channel opens or growing per-channel buffer usage.