A stack-based out-of-bounds read vulnerability exists in stunnel's 's_vlog' function when handling oversized log messages via 'vsnprintf'. A remote attacker with network access to a stunnel service can send protocol inputs that trigger log messages longer than 1024 bytes, potentially leading to a crash or replacement of trailing 'n' characters with '0' in certain cases. The CVE record was published on 202 [truncated]
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in stunnel 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses or unspecified addresses, enabling access to loopback-only services on the stunnel host that should not be network-reachable. The vulnerability can be mitigated by updating stu [truncated]