Dest Unreach's vulnerability profile centers on socat, a niche but critical utility for bidirectional data relay and socket forwarding that sees deployment in specialized networking and system administration contexts. The modest disclosure volume reflects the tool's focused scope rather than widespread adoption; defenders using socat in production environments should monitor this vendor's advisories closely. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dest Unreach over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56123CRITICAL socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploitin | Jun 25, 2026 | 9.8 | 40 | NO | NO |
CVE-2024-54661CRITICAL readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file. | Dec 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2010-2799MEDIUM Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows co | Sep 14, 2010 | 6.8 | 23 | NO | NO |
CVE-2015-1379HIGH The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash). | Jun 8, 2017 | 7.5 | 20 | NO | NO |
CVE-2016-2217MEDIUM The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret. | Jan 30, 2017 | 5.3 | 20 | NO | NO |
CVE-2012-0219MEDIUM Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary | Jun 21, 2012 | 6.2 | 19 | NO | NO |
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server na | Feb 4, 2014 | 1.9 | 14 | NO | NO |
socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service | May 8, 2014 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dest Unreach.
Media articles that mention a CVE ID that affects a product developed by Dest Unreach — matched by CVE ID, not by vendor name.