GO · JULY 2026 · EARLY WARNING

Integer Overflow Vulnerability in frp SSH Tunnel Gateway

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-26GQ-P25F-99CPSeverity: HIGH

An integer-overflow vulnerability in the frp server's SSH Tunnel Gateway appears to allow any unauthenticated remote attacker to crash the entire `frps` process with a single five-byte message. This vulnerability is reportedly reachable pre-authentication and can lead to a sustained denial of service.

What happened

An integer-overflow vulnerability has been reported in the frp server's SSH Tunnel Gateway, tracked under GHSA-26GQ-P25F-99CP. This vulnerability, if exploited, allows an unauthenticated remote attacker to crash the `frps` process with a minimal five-byte message. The issue is present in versions ranging from 0.53.0 to 0.70.0 of the frp (go) component. The attack is pre-authentication, meaning it can be executed without any prior authentication, potentially leading to a sustained denial of service. The situation is under investigation, and it is recommended to monitor for patches and upgrade to a fixed version once available. Primary sources should be consulted for the most current information.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If frp is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats