logo

Warning: Critical Vulnerability in Squid Web Proxy Cache, Patch Immediately!

ID: 6ddc0fba-2842-5757-90fe-4ed05d30d31f

STIX ID: report--6ddc0fba-2842-5757-90fe-4ed05d30d31f

Feed Name: CCB Advisories Feed

Threat Score
78/100

Date Published: 2025-08-05

Date Updated: 2026-07-24

...
...

Last updated 05-08-2025: A critical heap-based buffer overflow (CVE-2025-54574, CVSS 9.3) was disclosed in Squid Web Proxy Cache prior to v6.4 affecting many 4.x–6.x releases; the flaw in URN Trivial-HTTP response handling allows remote, unauthenticated attackers to cause memory disclosure or remote code execution. Patches are available in Squid 6.4 and stable patches; the Centre for Cybersecurity Belgium recommends immediate patching, disabling URN access as a temporary mitigation, and enhanced monitoring, though no in-the-wild exploitation has been reported in the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.