HIGH
jpillora
CVE published 2026-08-03
CVE-2026-48113
Authenticated clients can bypass ACL restrictions in Chisel versions prior to 1.11.5, tunneling traffic to arbitrary destinations. This issue is fixed in version 1.11.5. The vulnerability allows malicious clients to authenticate with a permitted remote and then open channels to any host:port they want, potentially leading to unauthorized traffic tunneling. Defenders of Chisel servers and networks should a [truncated]