Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-81535

wolfSSH admits forwarded-tcpip channels without authorization check

wolfSSH CVE-2026-81535 lets a malicious SSH peer open forwarded-tcpip channels that the forwarding policy callback never approved, making the endpoint allocate buffers for unauthorized forwarding channels. wolfSSL rates it Medium, CVSS 4.0 6.3. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.

CVSS
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Class
Other
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
wolfSSL
Products
wolfSSH
Affected
wolfSSH 1.4.8 through 1.5.0 built with --enable-fwd (TCP forwarding).
Fixed
wolfSSH 1.6.0 or later.
Published
7 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-81535 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets a malicious SSH peer open forwarded-tcpip channels that the forwarding policy callback never approved, making the endpoint allocate buffers for unauthorized forwarding channels.

wolfSSL's advisory says that with --enable-fwd, forwarded-tcpip channel opens were admitted without consulting the forwarding policy callback, and a client accepted them for forwards it never requested with tcpip-forward. A peer could make an endpoint allocate buffers for forwarding channels the application never authorized. The CVE record adds that these opens were not capped in number, so per-channel buffer allocation was unbounded. It also says a malicious server could open forwarding channels for addresses and ports the client never asked it to forward, contrary to RFC 4254 section 7.2.

The issue only affects builds with TCP forwarding enabled. wolfSSL classifies the impact as resource allocation for unauthorized channels; the CNA CVSS vector rates availability impact as low and confidentiality and integrity as none.

wolfSSL rates the issue Medium. wolfSSL, acting as CNA, scores it CVSS 4.0 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-862, CWE-863. Affected versions: wolfSSH 1.4.8 through 1.5.0 built with --enable-fwd (TCP forwarding). The fix landed in PRs #1059, #1148 and #1220 and ships in 1.6.0. wolfSSL credits zhangph (GitHub afldl).

The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: no). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-cqr9-f685-gr3w is unreviewed.

This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-81535