PatchSiren cyber security CVE debrief
CVE-2026-48113 jpillora CVE debrief
Authenticated clients can bypass ACL restrictions in Chisel versions prior to 1.11.5, tunneling traffic to arbitrary destinations. This issue is fixed in version 1.11.5. The vulnerability allows malicious clients to authenticate with a permitted remote and then open channels to any host:port they want, potentially leading to unauthorized traffic tunneling. Defenders of Chisel servers and networks should assess exposure and prioritize upgrading to version 1.11.5. The CVE record and NVD entry provide details on the vulnerability and its fix.
- Vendor
- jpillora
- Product
- chisel
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-09-10
Who should care
Defenders of Chisel servers and networks should assess exposure and prioritize upgrading to version 1.11.5. Operators of Chisel servers, security teams, and vulnerability management teams should review the CVE record and NVD entry to validate affected scope, severity, and vendor guidance. They should also verify exposure, review compensating controls, and monitor for suspicious traffic patterns.
Why it matters
Authenticated clients can bypass ACL restrictions in Chisel versions prior to 1.11.5, potentially leading to unauthorized traffic tunneling.
- Verify Chisel server exposure to unauthorized traffic
- Assess and update ACL configurations to prevent bypass
- Monitor for suspicious traffic patterns
Technical summary
Authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server in Chisel versions prior to 1.11.5. This issue has been fixed in version 1.11.5. The vulnerability allows malicious clients to authenticate with a permitted remote and then open channels to any host:port they want, potentially leading to unauthorized traffic tunneling. Defenders should prioritize verifying exposure of Chisel servers and upgrading to version 1.11.5. The CVE record and NVD entry provide details on the vulnerability and its fix.
Defensive priority
Defenders should prioritize verifying exposure of Chisel servers and upgrading to version 1.11.5.
Recommended defensive actions
- Verify Chisel server exposure and upgrade to version 1.11.5
- Review and update ACL configurations
- Monitor for suspicious traffic
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and its fix in Chisel version 1.11.5. Evidence from the CVE Program and NIST NVD detail page confirms the vulnerability and its impact. The issue has been fixed in version 1.11.5, and defenders should verify exposure and upgrade to this version. The CVE record was published on 2026-08-03T21:16:39.597Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48113 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48113
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48113 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48113
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/jpillora/chisel/commit/44310b65667a97901874ffdf4815b3732c22eaa3
-
Source reference
Unverified legacy reference
URL: https://github.com/jpillora/chisel/security/advisories/GHSA-24fp-5v3p-rvpw
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.