GHSA-26gq-p25f-99cp: frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
Summary
An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire frps process with a single five-byte message. When the gateway parses an SSH exec channel request in pkg/ssh/server.go, it adds a small constant to a four-byte length value taken directly from the request. Because that length is fully attacker-controlled, a value of 0xFFFFFFFF makes the addition wrap around to a tiny number, defeating the only bounds check and forcing an out-of-range slice. Go raises a panic that nothing recovers, so the whole server exits. In the default gateway mode SSH clients are not authenticated and the request is handled before any frp token is checked, so the crash is reachable pre-authentication. It carries no state and is trivially repeatable, turning one crash into a sustained outage that drops every tunnel for every user.
Details
The exec request payload is a four-byte big-endian length followed by that many command bytes, and the length field is fully attacker-controlled. The gateway computes the end of the command as 4 + length. The constant 4 takes the uint32 type of the length field, so 4 + 0xFFFFFFFF wraps modulo 2^32 to 3. The only guard compares the real payload size against this wrapped value, so a five-byte payload passes the test 5 < 3, and the slice runs from index 4 to index 3:
// pkg/ssh/server.go:315-319
end := 4 + binary.BigEndian.Uint32(req.Payload[:4]) // 4 + 0xFFFFFFFF wraps to 3
if len(req.Payload) < int(end) { // 5 < 3 is false, so it passes
continue
}
extraPayload := string(req.Payload[4:end]) // payload[4:3] -> panic
The handler runs in a bare goroutine and no function in the call chain installs a recover, so the panic unwinds to the top of the goroutine and terminates the whole process rather than the single connection:
// pkg/ssh/server.go:226
go s.handleNewChannel(newChannel, extraPayloadCh) // no recover anywhere in the chain
The sink is reachable without cred
Details
Original advisory: https://github.com/advisories/GHSA-26gq-p25f-99cp
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31