CVE-2026-70368
Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
CVSS Score
6.5
EPSS Score
0.4%
EPSS Percentile
28th
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".
| CWE | CWE-125 |
| Vendor | mobi-com polska sp. z o.o. |
| Product | stunnel |
| Published | Aug 4, 2026 |
| Last Updated | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for mobi-com polska sp. z o.o. stunnel
Be the first to know when new medium vulnerabilities affecting mobi-com polska sp. z o.o. stunnel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
Mobi-Com Polska Sp. z o.o. / stunnel
5.68 < 5.80
Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 6
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected References
Credits
This issue was discovered by Found by AISLE in partnership with Red Hat.