VYPR

Squidex

by Squidex

Source repositories

CVEs (157)

  • CVE-2020-8449HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • CVE-2016-10003HigJan 27, 2017
    risk 0.49cvss 7.5epss 0.05

    Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

  • CVE-2016-10002HigJan 27, 2017
    risk 0.49cvss 7.5epss 0.07

    Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted…

  • CVE-2016-2571HigFeb 27, 2016
    risk 0.49cvss 7.5epss 0.09

    http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

  • CVE-2016-2570HigFeb 27, 2016
    risk 0.49cvss 7.5epss 0.09

    The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to…

  • CVE-2021-31807MedJun 8, 2021
    risk 0.47cvss 6.5epss 0.16

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic…

  • CVE-2019-18679HigNov 26, 2019
    risk 0.45cvss 7.5epss 0.41

    An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation.…

  • CVE-2023-46252MedNov 7, 2023
    risk 0.44cvss 6.8epss 0.00

    Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which…

  • CVE-2021-31808MedMay 27, 2021
    risk 0.43cvss 6.5epss 0.05

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.

  • CVE-2020-15811MedSep 2, 2020
    risk 0.43cvss 6.5epss 0.04

    An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local…

  • CVE-2020-14059MedJun 30, 2020
    risk 0.43cvss 6.5epss 0.04

    An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Mem::PageStack::pop ABA problem during access to the memory page/slot management list.

  • CVE-2026-33526HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.09

    Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid…

  • CVE-2026-32748HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.09

    Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable…

  • CVE-2022-41317MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

  • CVE-2020-15810MedSep 2, 2020
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local…

  • CVE-2019-18676HigNov 26, 2019
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security…

  • CVE-2026-41172HigApr 22, 2026
    risk 0.40cvss epss 0.00

    Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and…

  • CVE-2026-41171HigApr 22, 2026
    risk 0.40cvss epss 0.00

    Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functions (`getJSON`,…

  • CVE-2026-41170HigApr 22, 2026
    risk 0.40cvss epss 0.00

    Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is fetched using the…

  • CVE-2023-24278MedMar 18, 2023
    risk 0.40cvss 6.1epss 0.03

    Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.

Page 3 of 8