Skip to main content

Vendor/product archive

squid-cache / squid CVEs

Beta · best-effort

111 CVEs tagged to squid-cache / squid11 Critical, 47 High, 50 Medium, 3 Low, 0 Unrated.

CVE-2026-50012

Published Jul 16, 2026

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is v…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-47729

Published Jul 16, 2026

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulner…

CVSS 6.5 · Medium
evidence mentions
13
Buzz score
46.4
Vendor/product tagsBeta · best-effort

CVE-2026-33526

Published Mar 26, 2026

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a r…

CVSS 9.2 · Critical
evidence mentions
18
Buzz score
43.9
Vendor/product tagsBeta · best-effort

CVE-2026-33515

Published Mar 26, 2026

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem all…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-32748

Published Mar 26, 2026

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Deni…

CVSS 8.7 · High
evidence mentions
18
Buzz score
43.9
Vendor/product tagsBeta · best-effort

CVE-2025-62168

Published Oct 17, 2025

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vuln…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59362

Published Sep 26, 2025

Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54574

Published Aug 1, 2025

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45802

Published Oct 28, 2024

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37894

Published Jun 25, 2024

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corr…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25617

Published Feb 14, 2024

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Se…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23638

Published Jan 24, 2024

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50269

Published Dec 14, 2023

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49288

Published Dec 4, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49286

Published Dec 4, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49285

Published Dec 4, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messa…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46728

Published Nov 6, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5824

Published Nov 3, 2023

A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46847

Published Nov 3, 2023

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is config…

CVSS 8.6 · High

CVE-2023-46846

Published Nov 3, 2023

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend securi…

CVSS 9.3 · Critical

CVE-2022-41318

Published Dec 25, 2022

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41317

Published Dec 25, 2022

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about client…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 111 CVEsPage 1 of 5