Integer Overflow Vulnerability in frp SSH Tunnel Gateway
An integer-overflow vulnerability has been reported in the frp server's optional SSH Tunnel Gateway, potentially allowing any unauthenticated remote attacker to crash the entire `frps` process with a single five-byte message.
What happened
An integer-overflow vulnerability, tracked as GHSA-26GQ-P25F-99CP, has been identified in the frp server's optional SSH Tunnel Gateway. This vulnerability reportedly allows any unauthenticated remote attacker to crash the entire `frps` process with a single five-byte message. The vulnerability appears to affect versions of frp (go) from 0.53.0 to 0.70.0. The issue is currently under investigation, and it is recommended to upgrade to a version of `frp` that includes the fix for this vulnerability. For more details, consult the primary sources.
How 0Day mitigates this
frp is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.