What is CVE-2026-70368?
CVE-2026-70368 is a stack-based out-of-bounds read vulnerability in the "s_vlog" function of stunnel. A remote attacker with network access can trigger an oversized log message via protocol inputs to read beyond the buffer. Upgrade stunnel to the latest patched version.
Azərbaycanca: CVE-2026-70368 stunnel proqramının "s_vlog" funksiyasında stack-based out-of-bounds read zəifliyidir. Uzaqdan şəbəkə girişi olan hücumçu 1024 baytdan uzun log mesajı yaradaraq məlumat sızmasına səbəb ola bilər. stunnel-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which function of stunnel was CVE-2026-70368 discovered?
The vulnerability was discovered in the "s_vlog" function of stunnel.
How can an attacker exploit CVE-2026-70368?
A remote attacker with network access can trigger an oversized log message via protocol inputs, causing a stack-based out-of-bounds read that may lead to information disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.