Shadowsocks is a lightweight proxy and circumvention tool distributed across several implementation variants (libev, ShadowsocksX-NG, and others), where the compact codebase has exhibited vulnerabilities centered on authentication bypass, code-integrity issues, and command-injection risks. The recurring weakness pattern—missing authentication for critical functions, unsafe code downloads, and OS command injection—reflects the tool's role as a network intermediary and the input-validation demands inherent to proxy implementations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shadowsocks over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15924HIGH In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP | Oct 27, 2017 | 7.8 | 25 | NO | NO |
CVE-2023-27574CRITICAL ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS. | Mar 3, 2023 | 9.8 | 24 | NO | NO |
CVE-2019-5163HIGH An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP pa | Dec 3, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-5152HIGH An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially craf | Dec 18, 2019 | 7.4 | 23 | NO | NO |
CVE-2019-5164HIGH An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary | Dec 3, 2019 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shadowsocks.
Media articles that mention a CVE ID that affects a product developed by Shadowsocks — matched by CVE ID, not by vendor name.