logo

29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview

ID: 2cc899c9-959a-5b36-a073-bdfe8baea03d

STIX ID: report--2cc899c9-959a-5b36-a073-bdfe8baea03d

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Guru Baran

...
...

Squidbleed is a critical heap-buffer overread in Squid Proxy, present since a 1997 commit, that can read up to ~4KB of adjacent heap memory and leak stale HTTP request data (including Authorization headers and API keys) via a malformed FTP directory listing; the flaw arises from misusing C's strchr on a null terminator, a PoC has been published and a one-line null-check patch has been merged, and administrators are advised to disable FTP proxy support unless required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.