<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:59:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352265</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352265</link>
      <description>EUVD-2026-352265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352265</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73564</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73564</link>
      <description>&lt;p&gt;frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp&amp;#39;s optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats the payload bounds check, and causes payload[4:3] to panic in TunnelServer.handleNewChannel. When no authorized-keys file is configured, sshConfig.NoClientAuth permits an unauthenticated peer to reach this channel phase before the frp token is checked, so a single five-byte request terminates the frps process and drops every active tunnel. This issue is fixed in version 0.70.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp&amp;#39;s optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats the payload bounds check, and causes payload[4:3] to panic in TunnelServer.handleNewChannel. When no authorized-keys file is configured, sshConfig.NoClientAuth permits an unauthenticated peer to reach this channel phase before the frp token is checked, so a single five-byte request terminates the frps process and drops every active tunnel. This issue is fixed in version 0.70.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73564</guid>
    </item>
    <item>
      <title>GHSA-26gq-p25f-99cp — frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-26gq-p25f-99cp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/fatedier/frp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An integer-overflow vulnerability in the frp server&amp;#39;s optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire `frps` process with a single five-byte message. When the gateway parses an SSH `exec` channel request in `pkg/ssh/server.go`, it adds a small constant to a four-byte length value taken directly from the request. Because that length is fully attacker-controlled, a value of `0xFFFFFFFF` makes the addition wrap around to a tiny number, defeating the only bounds check and forcing an out-of-range slice. Go raises a panic that nothing recovers, so the whole server exits. In the default gateway mode SSH clients are not authenticated and the request is handled before any frp token is checked, so the crash is reachable pre-authentication. It carries no state and is trivially repeatable, turning one crash into a sustained outage that drops every tunnel for every user.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `exec` request payload is a four-byte big-endian length followed by that many command bytes, and the length field is fully attacker-controlled. The gateway computes the end of the command as `4 + length`. The constant `4` takes the `uint32` type of the length field, so `4 + 0xFFFFFFFF` wraps modulo 2^32 to `3`. The only guard compares the real payload size against this wrapped value, so a five-byte payload passes the test `5 &amp;lt; 3`, and the slice runs from index 4 to index 3:&lt;/p&gt;
&lt;p&gt;```go
// pkg/ssh/server.go:315-319
end := 4 + binary.BigEndian.Uint32(req.Payload…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/fatedier/frp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An integer-overflow vulnerability in the frp server&amp;#39;s optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire `frps` process with a single five-byte message. When the gateway parses an SSH `exec` channel request in `pkg/ssh/server.go`, it adds a small constant to a four-byte length value taken directly from the request. Because that length is fully attacker-controlled, a value of `0xFFFFFFFF` makes the addition wrap around to a tiny number, defeating the only bounds check and forcing an out-of-range slice. Go raises a panic that nothing recovers, so the whole server exits. In the default gateway mode SSH clients are not authenticated and the request is handled before any frp token is checked, so the crash is reachable pre-authentication. It carries no state and is trivially repeatable, turning one crash into a sustained outage that drops every tunnel for every user.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `exec` request payload is a four-byte big-endian length followed by that many command bytes, and the length field is fully attacker-controlled. The gateway computes the end of the command as `4 + length`. The constant `4` takes the `uint32` type of the length field, so `4 + 0xFFFFFFFF` wraps modulo 2^32 to `3`. The only guard compares the real payload size against this wrapped value, so a five-byte payload passes the test `5 &amp;lt; 3`, and the slice runs from index 4 to index 3:&lt;/p&gt;
&lt;p&gt;```go
// pkg/ssh/server.go:315-319
end := 4 + binary.BigEndian.Uint32(req.Payload…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-26gq-p25f-99cp</guid>
    </item>
  </channel>
</rss>
