VYPR

Squid

by Squid Cache

Source repositories

CVEs (148)

  • CVE-2026-50012MedJul 16, 2026
    risk 0.36cvss 5.5epss 0.01

    Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the…

  • CVE-2026-33515MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.01

    Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive…

  • CVE-2019-18677MedNov 26, 2019
    risk 0.33cvss 6.1epss 0.07

    An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins…

  • CVE-2021-28652MedMay 27, 2021
    risk 0.32cvss 4.9epss 0.04

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an…

  • CVE-2019-12522MedApr 15, 2020
    risk 0.29cvss 4.5epss 0.00

    An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has…

  • CVE-2019-18678MedNov 26, 2019
    risk 0.28cvss 5.3epss 0.11

    An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid)…

  • CVE-2021-28116LowMar 9, 2021
    risk 0.25cvss 3.7epss 0.13

    Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

  • CVE-2016-4053LowApr 25, 2016
    risk 0.25cvss 3.7epss 0.14

    Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.

  • CVE-2013-4123Sep 16, 2013
    risk 0.09cvss epss 0.80

    client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.

  • CVE-2009-0478Feb 8, 2009
    risk 0.09cvss epss 0.72

    Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

  • CVE-2024-25617MedFeb 14, 2024
    risk 0.07cvss 5.3epss 0.89

    Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to…

  • CVE-2023-49285HigDec 4, 2023
    risk 0.07cvss 8.6epss 0.89

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no…

  • CVE-2021-28662MedMay 27, 2021
    risk 0.06cvss 6.5epss 0.72

    An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

  • CVE-2019-13345MedJul 5, 2019
    risk 0.06cvss 6.1epss 0.74

    The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

  • CVE-2014-7141Nov 26, 2014
    risk 0.06cvss epss 0.76

    The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

  • CVE-2005-0241May 2, 2005
    risk 0.06cvss epss 0.70

    The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

  • CVE-2005-0095Jan 15, 2005
    risk 0.06cvss epss 0.69

    The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.

  • CVE-2025-62168CriOct 17, 2025
    risk 0.05cvss 10.0epss 0.63

    Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted…

  • CVE-2024-23638MedJan 24, 2024
    risk 0.05cvss 6.5epss 0.60

    Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error…

  • CVE-2010-3072Sep 20, 2010
    risk 0.05cvss epss 0.64

    The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

Page 4 of 8