Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, avoid exposing stunnel services to untrusted clients. Restrict access to these services to trusted networks only.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stunnel
Stunnel stunnel |
|
| Vendors & Products |
Stunnel
Stunnel stunnel |
Tue, 04 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Tue, 04 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0". | |
| Title | stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-04T14:21:27.297Z
Reserved: 2026-08-04T07:03:23.572Z
Link: CVE-2026-70368
Updated: 2026-08-04T14:21:23.598Z
No data.
OpenCVE Enrichment
Updated: 2026-08-04T14:00:03Z