VendorsSquid-cachesquidall versions
Vulnerabilities

Squid-cache .org Squid

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

111CVEs
CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling
Published 2025-10-17 · Modified
10.0EPSS 0.634
CVE-2020-15049
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
Published 2020-06-30 · Modified
9.9EPSS 0.057
CVE-2020-11945
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
Published 2020-04-23 · Modified
9.8EPSS 0.272
CVE-2019-12525
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1.
Published 2019-07-11 · Modified
9.8EPSS 0.244
CVE-2025-54574
Squid's URN Handling can lead to Buffer Overflow
Published 2025-08-01 · Modified
9.8EPSS 0.227
CVE-2019-12526
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.
Published 2019-11-26 · Modified
9.8EPSS 0.203
CVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
Published 2020-04-15 · Modified
9.8EPSS 0.067
CVE-2019-12524
An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.
Published 2020-04-15 · Modified
9.8EPSS 0.043
CVE-2023-46846
Squid: request/response smuggling in http/1.1 and icap
Published 2023-11-03 · Modified
9.3EPSS 0.062
CVE-2026-33526
Squid vulnerable to Denial of Service in ICP Request handling
Published 2026-03-26 · Modified
9.2EPSS 0.089
CVE-2019-12523
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.
Published 2019-11-26 · Modified
9.1EPSS 0.043
CVE-2019-12527
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Published 2019-07-11 · Modified
8.8EPSS 0.490
CVE-2016-4051
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
Published 2016-04-25 · Modified
8.8EPSS 0.183
CVE-2026-32748
Squid has Denial of Service in ICP Response handling
Published 2026-03-26 · Modified
8.7EPSS 0.089
CVE-2023-46847
Squid: denial of service in http digest authentication
Published 2023-11-03 · Modified
8.6EPSS 0.884
CVE-2023-49285
Denial of Service in HTTP Message Processing in Squid
Published 2023-12-04 · Modified
8.6EPSS 0.881
CVE-2016-4553
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Published 2016-05-10 · Modified
8.6EPSS 0.800
CVE-2024-25111
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
Published 2024-03-06 · Modified
8.6EPSS 0.653
CVE-2023-50269
SQUID-2023:10 Denial of Service in HTTP Request parsing
Published 2023-12-14 · Modified
8.6EPSS 0.576
CVE-2016-4554
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
Published 2016-05-10 · Modified
8.6EPSS 0.389
CVE-2023-49286
Denial of Service in Helper Process management
Published 2023-12-04 · Modified
8.6EPSS 0.104
CVE-2023-46848
Squid: denial of service in ftp
Published 2023-11-03 · Modified
8.6EPSS 0.102
CVE-2020-25097
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
Published 2021-03-19 · Modified
8.6EPSS 0.082
CVE-2020-24606
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.
Published 2020-08-24 · Modified
8.6EPSS 0.052
CVE-2023-49288
Denial of Service in HTTP Collapsed Forwarding in Squid
Published 2023-12-04 · Modified
8.6EPSS 0.048
CVE-2023-46724
SQUID-2023:4 Denial of Service in SSL Certificate validation
Published 2023-11-01 · Modified
8.6EPSS 0.040
CVE-2022-41318
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.
Published 2022-12-25 · Modified
8.6EPSS 0.028
CVE-2016-3947
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
Published 2016-04-07 · Modified
8.2EPSS 0.146
CVE-2016-4054
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
Published 2016-04-25 · Modified
8.1EPSS 0.776
CVE-2016-4052
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
Published 2016-04-25 · Modified
8.1EPSS 0.129
CVE-2013-1839
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.
Published 2013-09-30 · Modified
7.8EPSS 0.183
CVE-2024-25617
Denial of Service in HTTP Header parser in squid proxy
Published 2024-02-14 · Analyzed
7.5EPSS 0.881
CVE-2020-8450
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Published 2020-02-04 · Modified
7.5EPSS 0.718
CVE-2016-4555
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
Published 2016-05-10 · Modified
7.5EPSS 0.539
CVE-2024-45802
Squid Denial of Service
Published 2024-10-28 · Modified
7.5EPSS 0.479
CVE-2013-4115
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.
Published 2013-08-09 · Modified
7.5EPSS 0.433
CVE-2019-18679
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
Published 2019-11-26 · Modified
7.5EPSS 0.410
CVE-2016-3948
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
Published 2016-04-07 · Modified
7.5EPSS 0.353
CVE-2016-2569
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Published 2016-02-27 · Modified
7.5EPSS 0.312
CVE-2016-4556
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
Published 2016-05-10 · Modified
7.5EPSS 0.231
1 / 3Next →