Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70367

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.

Отчет

When configured with "protocol = socks", which is a non-default setting, an attacker able to reach the SOCKS server can send requests that will get proxied to localhost. This potentially exposes services bound to the local interface of the "stunnel" host. Exploitation depends on the presence and security of such local services. A SOCKS proxy is intentionally a general-purpose network access facility and should always be deployed with appropriate firewall policies and client authorization, i.e., there should be no untrusted users accessing a SOCKS proxy.

Меры по смягчению последствий

To mitigate this issue, if SOCKS proxying functionality is not required, disable the "protocol = socks" configuration in "stunnel". If SOCKS proxying is necessary, restrict access to the SOCKS listener by binding it to a trusted management network or localhost, and enforce client authentication or network ACL controls. Run "stunnel" in a container or network namespace where no other services are bound to localhost, or add firewall rules to restrict outgoing connections from "stunnel" to localhost.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10stunnelFix deferred
Red Hat Enterprise Linux 6stunnelNot affected
Red Hat Enterprise Linux 7stunnelNot affected
Red Hat Enterprise Linux 8stunnelFix deferred
Red Hat Enterprise Linux 9stunnelFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2462083stunnel: SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services

EPSS

Процентиль: 5%
0.00156
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
27 дней назад

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.

CVSS3: 5.4
nvd
27 дней назад

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.

msrc
25 дней назад

Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services

CVSS3: 5.4
debian
27 дней назад

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in \u ...

CVSS3: 5.4
github
27 дней назад

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.

EPSS

Процентиль: 5%
0.00156
Низкий

5.4 Medium

CVSS3