CVE-2026-70367: Server-Side Request Forgery (SSRF) in Mobi-Com Polska Sp. z o.o. stunnel
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.
AI Analysis
Technical Summary
The vulnerability exists in stunnel 5.79 and earlier when configured with the non-default setting "protocol = socks". An attacker able to reach the SOCKS proxy can send requests that bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) or unspecified addresses (0.0.0.0, ::). This enables access to services bound to the local interface of the stunnel host that should not be reachable over the network. The SOCKS proxy is a general-purpose network access facility and should be deployed with strict firewall and client authorization controls. The vulnerability does not affect default configurations without SOCKS proxy enabled. Red Hat's advisory emphasizes that exploitation depends on the security of local services and recommends restricting access to the SOCKS listener or disabling SOCKS proxying if not needed.
Potential Impact
This vulnerability allows an attacker with network access to the stunnel SOCKS proxy to bypass localhost access restrictions and potentially interact with local services that are not intended to be exposed externally. The impact includes limited confidentiality and integrity risks, as attackers might read application data or execute unauthorized commands via local services. There is no impact on availability. Exploitation requires the SOCKS proxy mode to be enabled and accessible to the attacker.
Mitigation Recommendations
If SOCKS proxying is not required, disable the "protocol = socks" setting in stunnel. If SOCKS proxying is necessary, restrict access to the SOCKS listener by binding it to a trusted management network or localhost, and enforce client authentication or network ACLs. Running stunnel in isolated containers or network namespaces without other services bound to localhost, or applying firewall rules to restrict outgoing connections from stunnel to localhost, can further mitigate the risk. No official patch or fix is currently confirmed; check the vendor advisory for updates.
CVE-2026-70367: Server-Side Request Forgery (SSRF) in Mobi-Com Polska Sp. z o.o. stunnel
Description
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.
CVSS v3.1
Score 5.4medium
Affected software
Mobi-Com Polska Sp. z o.o.
stunnel
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in stunnel 5.79 and earlier when configured with the non-default setting "protocol = socks". An attacker able to reach the SOCKS proxy can send requests that bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) or unspecified addresses (0.0.0.0, ::). This enables access to services bound to the local interface of the stunnel host that should not be reachable over the network. The SOCKS proxy is a general-purpose network access facility and should be deployed with strict firewall and client authorization controls. The vulnerability does not affect default configurations without SOCKS proxy enabled. Red Hat's advisory emphasizes that exploitation depends on the security of local services and recommends restricting access to the SOCKS listener or disabling SOCKS proxying if not needed.
Potential Impact
This vulnerability allows an attacker with network access to the stunnel SOCKS proxy to bypass localhost access restrictions and potentially interact with local services that are not intended to be exposed externally. The impact includes limited confidentiality and integrity risks, as attackers might read application data or execute unauthorized commands via local services. There is no impact on availability. Exploitation requires the SOCKS proxy mode to be enabled and accessible to the attacker.
Mitigation Recommendations
If SOCKS proxying is not required, disable the "protocol = socks" setting in stunnel. If SOCKS proxying is necessary, restrict access to the SOCKS listener by binding it to a trusted management network or localhost, and enforce client authentication or network ACLs. Running stunnel in isolated containers or network namespaces without other services bound to localhost, or applying firewall rules to restrict outgoing connections from stunnel to localhost, can further mitigate the risk. No official patch or fix is currently confirmed; check the vendor advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-04T07:03:23.572Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-70367","vendor":"Red Hat"}]
Threat ID: 6a71f358bf8831d539eaa4dc
Added to database: 08/04/2026, 14:12:40 UTC
Last enriched: 08/11/2026, 17:34:32 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.