Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.
https://www.stunnel.org/CVE-2015-3644.html
https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-3682
http://www.securitytracker.com/id/1032324