logo

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

ID: 9916129a-0ef2-5136-808f-69317267bf23

STIX ID: report--9916129a-0ef2-5136-808f-69317267bf23

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: [email protected] (The Hacker News)

...
...

Squidbleed (CVE-2026-47729) is a heap over-read in Squid's FTP directory-listing parser that can expose other users' cleartext HTTP requests (including Authorization headers and session tokens) to a trusted client of the same proxy; the flaw stems from improper handling of a null terminator in FTP listings, and researchers published PoC while recommending patch verification or disabling FTP as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.