Server-Side Request Forgery Vulnerability in Stunnel by OpenSSL
CVE-2026-70367
5.4MEDIUM
What is CVE-2026-70367?
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in Stunnel versions 5.79 and earlier when configured to operate in SOCKS proxy mode. This issue permits an attacker to bypass localhost restrictions, leveraging IPv4-mapped IPv6 addresses (like '::ffff:127.0.0.1') or unspecified addresses ('0.0.0.0', '::'). Consequently, this vulnerability allows unauthorized access to loopback-only services hosted on the Stunnel server.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.