{"id":"AZL-94577","summary":"CVE-2026-70367 affecting package stunnel 5.74-1","details":"A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses (\"0.0.0.0\", \"::\"), enabling access to loopback-only services on the \"stunnel\" host that should not be network-reachable.","modified":"2026-08-30T05:26:50Z","published":"2026-08-04T14:16:32Z","upstream":["CVE-2026-70367"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70367"}],"affected":[{"package":{"name":"stunnel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/stunnel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.74-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94577.json"}}],"schema_version":"1.9.0"}