CVE-2026-81535: wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check

Published Oct 7, 2026
·
Updated

In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.

Affected Software

1 affected component
wolfSSL wolfSSH<=1.5.0

Event History

Oct 7, 2026
CVE Published
via MITRE·02:39 AM
Data Sourced
via MITRE·02:39 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

wolfSSH installations through version 1.5.0 are affected when built with the --enable-fwd option. The issue concerns the SSH client when it connects to a malicious or compromised SSH peer.

2

What does an attacker need to exploit this?

The attacker needs to control, or be able to act as, the SSH server or peer connected to by the wolfSSH client. That peer can send unsolicited forwarded-tcpip channel-open requests without having an authorized or registered forwarding request.

3

What is the practical impact of exploitation?

A malicious peer can cause the endpoint to allocate per-channel forwarding buffers for channels the application did not authorize. Because forwarded-tcpip opens are not capped in number, this can result in unbounded resource consumption and channels associated with unrequested addresses and ports.

4

Is a default build affected?

The vulnerable behavior is present only in builds that enable forwarding with --enable-fwd. The supplied information does not establish whether that option is enabled by default.

5

How can I determine whether my environment is affected?

Check whether wolfSSH is version 1.5.0 or earlier and whether it was built with --enable-fwd. Review client connections to untrusted SSH servers, especially for unexpected forwarded-tcpip channel opens or growing per-channel buffer usage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203