PatchSiren

squid-cache CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM squid-cache CVE published 2026-07-16

CVE-2026-50012

CVE-2026-50012 is a heap-based buffer overflow vulnerability in Squid, a caching proxy for the Web. The vulnerability exists in the cache digest reply handling, specifically in the peerDigestSwapInMask function in src/peer_digest.cc. This function improperly validates input, allowing a trusted peer to send a maliciously crafted reply to a cache_digest request message, which can trigger the overflow. The a [truncated]

MEDIUM squid-cache CVE published 2026-07-16

CVE-2026-47729

CVE-2026-47729 is an out-of-bounds read vulnerability in Squid's FTP gateway feature. The issue arises from improper validation of syntactic correctness of input in the FTP gateway. This vulnerability allows a trusted client accessing a misbehaving FTP server through Squid's gateway feature to read memory from random unrelated transactions. The issue is fixed in Squid version 7.6. Affected deployments sho [truncated]

CRITICAL Squid Cache CVE published 2026-03-26

CVE-2026-33526

CVE-2026-33526 is a critical vulnerability in Squid, a caching proxy for the Web, which allows for Denial of Service attacks via ICP traffic. The vulnerability is caused by a heap Use-After-Free issue and has a CVSS score of 9.2. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. The attack is limited to Squid d [truncated]

HIGH Squid Cache CVE published 2026-03-26

CVE-2026-32748

CVE-2026-32748 is a high-severity vulnerability in Squid, a caching proxy for the Web. The vulnerability is caused by premature release of resource during expected lifetime and heap Use-After-Free bugs. This allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. The attack is limited to Squid deployments that explicitly enable I [truncated]

HIGH Squid Cache CVE published 2017-01-27

CVE-2016-10003

Squid HTTP Proxy versions 3.5.0.1-3.5.22 and 4.0.1-4.0.16 can mis-handle HTTP request header comparison in the Collapsed Forwarding feature, causing some private responses to be treated as suitable for delivery to multiple clients. Because the issue is network-reachable, requires no privileges or user interaction, and can expose confidential content, affected proxy deployments should be prioritized for up [truncated]

HIGH Squid Cache CVE published 2017-01-27

CVE-2016-10002

CVE-2016-10002 describes a Squid HTTP Proxy flaw where responses to conditional requests can be processed incorrectly, allowing client-specific Cookie data to be exposed to other clients. The issue affects multiple Squid release lines and is rated HIGH by NVD with a CVSS 3.0 score of 7.5. Because the attack can be crafted by a client to probe a shared cache, this is a confidentiality issue that matters mo [truncated]