Alpine: stunnel: security update to 5.82-r0

medium Tenable Self-Hosted Container Security Plugin ID 448462

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when
configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by
using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"),
enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.
(CVE-2026-70367)

- A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling
oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can
send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack
read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a
series of trailing "\n" characters with "\0". (CVE-2026-70368)

Solution

Update the stunnel library and its related packages to version 5.82-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-70367

https://security.alpinelinux.org/vuln/CVE-2026-70368

Plugin Details

Severity: Medium

ID: 448462

Version: Revision 1.1

Type: Local

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.89

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-70368

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/4/2026

Reference Information

CVE: CVE-2026-70367, CVE-2026-70368