CVE-2026-50012 is a heap-based buffer overflow vulnerability in Squid, a caching proxy for the Web. The vulnerability exists in the cache digest reply handling, specifically in the peerDigestSwapInMask function in src/peer_digest.cc. This function improperly validates input, allowing a trusted peer to send a maliciously crafted reply to a cache_digest request message, which can trigger the overflow. The a [truncated]
CVE-2026-47729 is an out-of-bounds read vulnerability in Squid's FTP gateway feature. The issue arises from improper validation of syntactic correctness of input in the FTP gateway. This vulnerability allows a trusted client accessing a misbehaving FTP server through Squid's gateway feature to read memory from random unrelated transactions. The issue is fixed in Squid version 7.6. Affected deployments sho [truncated]
CVE-2026-33526 is a critical vulnerability in Squid, a caching proxy for the Web, which allows for Denial of Service attacks via ICP traffic. The vulnerability is caused by a heap Use-After-Free issue and has a CVSS score of 9.2. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. The attack is limited to Squid d [truncated]
CVE-2026-32748 is a high-severity vulnerability in Squid, a caching proxy for the Web. The vulnerability is caused by premature release of resource during expected lifetime and heap Use-After-Free bugs. This allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. The attack is limited to Squid deployments that explicitly enable I [truncated]
Squid HTTP Proxy versions 3.5.0.1-3.5.22 and 4.0.1-4.0.16 can mis-handle HTTP request header comparison in the Collapsed Forwarding feature, causing some private responses to be treated as suitable for delivery to multiple clients. Because the issue is network-reachable, requires no privileges or user interaction, and can expose confidential content, affected proxy deployments should be prioritized for up [truncated]
CVE-2016-10002 describes a Squid HTTP Proxy flaw where responses to conditional requests can be processed incorrectly, allowing client-specific Cookie data to be exposed to other clients. The issue affects multiple Squid release lines and is rated HIGH by NVD with a CVSS 3.0 score of 7.5. Because the attack can be crafted by a client to probe a shared cache, this is a confidentiality issue that matters mo [truncated]