Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Shadowsocks

First CVE: Oct 27, 2017Active for: 9 yearsTotal CVEs: 5

Shadowsocks is a lightweight proxy and circumvention tool distributed across several implementation variants (libev, ShadowsocksX-NG, and others), where the compact codebase has exhibited vulnerabilities centered on authentication bypass, code-integrity issues, and command-injection risks. The recurring weakness pattern—missing authentication for critical functions, unsafe code downloads, and OS command injection—reflects the tool's role as a network intermediary and the input-validation demands inherent to proxy implementations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Shadowsocks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 27, 2017
8 years ago
Most Recent CVE
Mar 3, 2023
1,239 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15924HIGH
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP
Oct 27, 20177.825NONO
CVE-2023-27574CRITICAL
ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.
Mar 3, 20239.824NONO
CVE-2019-5163HIGH
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP pa
Dec 3, 20197.524NONO
CVE-2019-5152HIGH
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially craf
Dec 18, 20197.423NONO
CVE-2019-5164HIGH
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary
Dec 3, 20197.823NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
80%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (40.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Shadowsocks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Shadowsocks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Shadowsocks's Products

View all 2 CNAs →

Top CWEs