What is CVE-2026-70367?
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows an attacker to bypass localhost restrictions by using specially crafted IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses. It is recommended to immediately update “stunnel” to the latest version on affected systems.
Azərbaycanca: “stunnel” 5.79 və daha aşağı versiyalarda, SOCKS proxy rejimində konfiqurasiya edildikdə Server-Side Request Forgery (SSRF) bypass zəifliyi mövcuddur. Bu qüsur, təcavüzkara xüsusi IPv4-mapped IPv6 ünvanları (məsələn, “::ffff:127.0.0.1”) və ya təyin olunmamış ünvanlardan istifadə edərək localhost məhdudiyyətlərini keçməyə imkan verir. Təsirə məruz qalan sistemlərdə dərhal “stunnel” proqramını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of “stunnel” are affected by CVE-2026-70367?
CVE-2026-70367 affects “stunnel” 5.79 and lower versions.
How can an attacker exploit this SSRF bypass vulnerability?
An attacker can bypass localhost restrictions by using specially crafted IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.