Dear Users,
I have released version 5.80 of stunnel.
This is a security bugfix release. Details are available on:
### Version 5.80, 2026.08.04, urgency: HIGH
* Security bugfixes
- CVE-2026-70368: Fixed an out-of-bounds memory access triggered
by
logging attacker-controlled protocol messages longer than 1,024
bytes
(thanks to AISLE Research and Clemens Lang).
- CVE-2026-70367: Fixed a SOCKS server mode bypass of the
localhost
destination filter using alternate local-address encodings and
interface-scoped IPv6 destinations (thanks to AISLE Research and
Clemens Lang).
- Restricted Windows GUI/service control pipes to local clients.
* Bugfixes
- Fixed concurrent DTLS handshakes from clients sharing an IP
address.
- Fixed version reporting in builds from source.
- Rejected stream-oriented protocol negotiation with the UDP
transport
during configuration validation.
* Features
- Added the "CRLcheckChain" service-level option for opt-in
full-chain CRL verification.
Home page: https://www.stunnel.org/
Download: https://www.stunnel.org/downloads.html
SHA-256 hashes:
6d0841d48de07cbbaf4a055919065bf7bb5ebc63cc15c97a2c76caa2bf285513
stunnel-5.80.tar.gz
25947bd268e2e670e1c7f915cefd54585aaa440d09eb20c6109cdbeaf3140bc4
stunnel-5.80-win64-installer.exe
15a36d8641bcf885f13ce0ee858d1f07bf4798824093e54fd00eeeb526dcc5ab
stunnel-5.80-android.zip
Best regards,
Mike