CVE detail
CVE-2026-47729
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- CVE-2026-47729 Squid: Memory disclosure in FTP gatewayMicrosoft MSRC
Information published.
vendormsrc.microsoft.comJul 18, 2026, 8:01 AM No excerpt available.
Exploitgithub.comJul 16, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comJul 16, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comJul 16, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comJul 16, 2026, 5:16 PMNo excerpt available.
Exploitgithub.comJul 16, 2026, 5:16 PMA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages Hospitality Sector Hit by […]
newssecurityaffairs.comJun 28, 2026, 3:29 PM- CVE-2026-47729Horizon3.ai
CVE-2026-47729 (Squidbleed) can expose credentials, cookies, API keys, and session tokens from memory in vulnerable Squid proxy deployments.
exploithorizon3.aiJun 24, 2026, 3:49 PM - Squidbleed: 29-Year-Old Squid Bug Leaks User CredentialsSecurity Affairs
Squidbleed is a 29-year-old Squid Proxy flaw that can leak credentials, tokens, and other users’ HTTP data through a memory overread. Researchers at Calif.io have disclosed CVE-2026-47729, a memory leak vulnerability in Squid Proxy that was introduced in 1997 and has remained undetected through nearly three decades of releases, audits, and rewrites. They named it […]
newssecurityaffairs.comJun 23, 2026, 7:09 AM Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.
newswww.securityweek.comJun 22, 2026, 1:22 PM- SquidbleedHacker News
Linked URL: https://blog.calif.io/p/squidbleed-cve-2026-47729 | Posted by Tomte | 2 points | 0 comments
communitynews.ycombinator.comJun 22, 2026, 11:56 AM Linked URL: https://blog.calif.io/p/squidbleed-cve-2026-47729 | Posted by chillax | 3 points | 0 comments
communitynews.ycombinator.comJun 19, 2026, 10:34 AM- Squidbleed (CVE-2026-47729)Hacker News
Linked URL: https://blog.calif.io/p/squidbleed-cve-2026-47729 | Posted by quyleanh | 5 points | 0 comments
communitynews.ycombinator.comJun 18, 2026, 7:38 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33515CVSS 6.9 · Medium
Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem all…
- CVE-2023-49285CVSS 8.6 · High
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messa…
- CVE-2023-46724CVSS 8.6 · High
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl`…
- CVE-2021-28116CVSS 3.7 · Low
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as pa…
- CVE-2019-12529CVSS 5.9 · Medium
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization he…
- CVE-2026-49282CVSS 5.1 · Medium
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected archit…