Warning: Critical Vulnerability in Squid Web Proxy Cache, Patch Immediately!
ID: 6ddc0fba-2842-5757-90fe-4ed05d30d31f
STIX ID: report--6ddc0fba-2842-5757-90fe-4ed05d30d31f
Feed Name: CCB Advisories Feed
Last updated 05-08-2025: A critical heap-based buffer overflow (CVE-2025-54574, CVSS 9.3) was disclosed in Squid Web Proxy Cache prior to v6.4 affecting many 4.x–6.x releases; the flaw in URN Trivial-HTTP response handling allows remote, unauthenticated attackers to cause memory disclosure or remote code execution. Patches are available in Squid 6.4 and stable patches; the Centre for Cybersecurity Belgium recommends immediate patching, disabling URN access as a temporary mitigation, and enhanced monitoring, though no in-the-wild exploitation has been reported in the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
