How to find Squid caching proxy installations on your network
ID: 1a97f92c-3dca-5b04-b103-3a7bf9034321
STIX ID: report--1a97f92c-3dca-5b04-b103-3a7bf9034321
Feed Name: runZero Blog
This advisory details two critical Squid proxy vulnerabilities: CVE-2025-62168 (information disclosure via unredacted error message expansions, CVSS 10.0) which can expose HTTP authentication credentials and tokens, and CVE-2025-54574 (heap-based buffer overflow, CVSS 9.3) which can lead to remote code execution or leakage of heap memory. Affected Squid versions across multiple major releases are listed, and recommended actions include upgrading to patched versions or applying configuration workarounds (e.g., `email_err_data off`, disabling URN access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
