logo

How to find Squid caching proxy installations on your network

ID: 1a97f92c-3dca-5b04-b103-3a7bf9034321

STIX ID: report--1a97f92c-3dca-5b04-b103-3a7bf9034321

Feed Name: runZero Blog

Threat Score
80/100

Date Published: 2025-08-04

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

This advisory details two critical Squid proxy vulnerabilities: CVE-2025-62168 (information disclosure via unredacted error message expansions, CVSS 10.0) which can expose HTTP authentication credentials and tokens, and CVE-2025-54574 (heap-based buffer overflow, CVSS 9.3) which can lead to remote code execution or leakage of heap memory. Affected Squid versions across multiple major releases are listed, and recommended actions include upgrading to patched versions or applying configuration workarounds (e.g., `email_err_data off`, disabling URN access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.