Squidbleed (CVE-2026-47729): Squid Proxy Memory Leak Details and PoC Disclosed
ID: ec8fd4cb-0df6-509a-b393-69f86dc46522
STIX ID: report--ec8fd4cb-0df6-509a-b393-69f86dc46522
Feed Name: securityonline.info
Threat Score
Researchers disclosed “Squidbleed” (CVE-2026-47729), a long-standing buffer/parser flaw in Squid's FTP directory-listing code that can leak other users’ cleartext HTTP requests (including Authorization headers, cookies, and API keys) to an attacker who controls an FTP server and shares the same proxy; a proof‑of‑concept is public, patches have been merged (Squid 7.6/7.7 contains the fix) and mitigations include verifying the patch or disabling FTP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
