29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
ID: 9916129a-0ef2-5136-808f-69317267bf23
STIX ID: report--9916129a-0ef2-5136-808f-69317267bf23
Feed Name: The Hacker News
Threat Score
Squidbleed (CVE-2026-47729) is a heap over-read in Squid's FTP directory-listing parser that can expose other users' cleartext HTTP requests (including Authorization headers and session tokens) to a trusted client of the same proxy; the flaw stems from improper handling of a null terminator in FTP listings, and researchers published PoC while recommending patch verification or disabling FTP as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
