Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services
Published Aug 4, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.26%
Description
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.
Affected products
-
- Version 5.25StatusaffectedConstraints<5.80
- Version
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mobi-Com Polska Sp. z o.o. | Stunnel | unaffected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
stunnel
Fix deferred
Red Hat Enterprise Linux 6
stunnel
Not affected
Red Hat Enterprise Linux 7
stunnel
Not affected
Red Hat Enterprise Linux 8
stunnel
Fix deferred
Red Hat Enterprise Linux 9
stunnel
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | stunnel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | stunnel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | stunnel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | stunnel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | stunnel | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, if SOCKS proxying functionality is not required, disable the "protocol = socks" configuration in "stunnel". If SOCKS proxying is necessary, restrict access to the SOCKS listener by binding it to a trusted management network or localhost, and enforce client authentication or network ACL controls. Run "stunnel" in a container or network namespace where no other services are bound to localhost, or add firewall rules to restrict outgoing connections from "stunnel" to localhost.
Red Hat statement
When configured with "protocol = socks", which is a non-default setting, an attacker able to reach the SOCKS server can send requests that will get proxied to localhost. This potentially exposes services bound to the local interface of the "stunnel" host. Exploitation depends on the presence and security of such local services. A SOCKS proxy is intentionally a general-purpose network access facility and should always be deployed with appropriate firewall policies and client authorization, i.e., there should be no untrusted users accessing a SOCKS proxy.
Red Hat mitigation
To mitigate this issue, if SOCKS proxying functionality is not required, disable the "protocol = socks" configuration in "stunnel". If SOCKS proxying is necessary, restrict access to the SOCKS listener by binding it to a trusted management network or localhost, and enforce client authentication or network ACL controls. Run "stunnel" in a container or network namespace where no other services are bound to localhost, or add firewall rules to restrict outgoing connections from "stunnel" to localhost.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-70367 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2462083 exploitissue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52687 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-70367
- https://www.cve.org/CVERecord?id=CVE-2026-70367
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-70367 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2462083 | exploitissue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52687 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-70367 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-70367 |
Change history (0)
No recorded changes yet.