29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
ID: 7c012aa7-c57c-5fd9-9dfd-41256e553fbe
STIX ID: report--7c012aa7-c57c-5fd9-9dfd-41256e553fbe
Feed Name: CosmicBytez Labs
Researchers disclosed "Squidbleed" (CVE-2026-47729), a heap over-read in Squid's FTP directory-listing parser that can expose cleartext HTTP request contents—such as Authorization headers, session tokens, cookies, and URLs—from adjacent freed buffers to an attacker-controlled FTP response. Exploitation requires the attacker be a permitted user of the same Squid instance and control an FTP server reachable by the proxy; HTTPS is not affected. Recommended mitigations are upgrading to Squid 7.7 (patch applied) or disabling FTP proxying.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
