logo

Squidbleed (CVE-2026-47729): Squid Proxy Memory Leak Details and PoC Disclosed

ID: ec8fd4cb-0df6-509a-b393-69f86dc46522

STIX ID: report--ec8fd4cb-0df6-509a-b393-69f86dc46522

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Do Son

...
...

Researchers disclosed “Squidbleed” (CVE-2026-47729), a long-standing buffer/parser flaw in Squid's FTP directory-listing code that can leak other users’ cleartext HTTP requests (including Authorization headers, cookies, and API keys) to an attacker who controls an FTP server and shares the same proxy; a proof‑of‑concept is public, patches have been merged (Squid 7.6/7.7 contains the fix) and mitigations include verifying the patch or disabling FTP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.