logo

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

ID: 7c012aa7-c57c-5fd9-9dfd-41256e553fbe

STIX ID: report--7c012aa7-c57c-5fd9-9dfd-41256e553fbe

Feed Name: CosmicBytez Labs

Threat Score
50/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

Researchers disclosed "Squidbleed" (CVE-2026-47729), a heap over-read in Squid's FTP directory-listing parser that can expose cleartext HTTP request contents—such as Authorization headers, session tokens, cookies, and URLs—from adjacent freed buffers to an attacker-controlled FTP response. Exploitation requires the attacker be a permitted user of the same Squid instance and control an FTP server reachable by the proxy; HTTPS is not affected. Recommended mitigations are upgrading to Squid 7.7 (patch applied) or disabling FTP proxying.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.