Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

squid — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in squid, with AI-generated Chinese analysis, references, and POCs.

This page documents common vulnerabilities, weaknesses, and threats associated with the squid software product developed by squid-cache.org. It aggregates security issues affecting this popular caching proxy, focusing on known exploitation vectors and configuration pitfalls. The collection includes a range of vulnerability types spanning from cross-site scripting and buffer overflows to privilege escalation and denial of service conditions. The data covers security advisories, patches, and incident reports from January 2000 through December 2023. This period reflects the mature lifecycle of the software, capturing both historical flaws and recent updates. By consulting this resource, users can effectively track vendor-specific security advisories issued by the squid-cache.org team. Additionally, researchers can deepen their understanding of specific weakness classes as they manifest within this particular proxy environment. System administrators may also review the product’s comprehensive vulnerability history to assess risk exposure and prioritize remediation efforts. The information is organized to facilitate quick lookup of known issues without listing individual CVE identifiers directly in the summary. This approach ensures a clear overview of the security landscape surrounding squid. Understanding these patterns helps in hardening configurations and deploying appropriate mitigation strategies. The page serves as a central reference for evaluating the security posture of squid deployments against established threat intelligence. It aims to provide actionable insights for maintaining robust and secure proxy infrastructure environments.

Vendor: squid-cache

CVE ID Title CVSS Severity Published
CVE-2026-47729 Squid: Memory disclosure in FTP gateway CWE-125 6.5 Medium 2026-07-16
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling CWE-20 5.5 Medium 2026-07-16
CVE-2026-33526 Squid vulnerable to Denial of Service in ICP Request handling CWE-416 7.5 - 2026-03-26
CVE-2026-33515 Squid has issues in ICP message handling CWE-125 5.3 - 2026-03-26
CVE-2026-32748 Squid has Denial of Service in ICP Response handling CWE-413 7.5 - 2026-03-26
CVE-2025-62168 Squid vulnerable to information disclosure via authentication credential leakage in error handling CWE-209 10.0 Critical 2025-10-17
CVE-2025-54574 Squid's URN Handling can lead to Buffer Overflow CWE-122 9.3 Critical 2025-08-01
CVE-2024-45802 Squid Denial of Service CWE-20 7.5 High 2024-10-28
CVE-2024-37894 Squid vulnerable to heap corruption in ESI assign CWE-787 6.3 Medium 2024-06-25
CVE-2024-25111 SQUID-2024:1 Denial of Service in HTTP Chunked Decoding CWE-674 8.6 High 2024-03-06
CVE-2024-25617 Denial of Service in HTTP Header parser in squid proxy CWE-400 5.3 Medium 2024-02-14
CVE-2024-23638 SQUID-2023:11 Denial of Service in Cache Manager CWE-825 6.5 Medium 2024-01-23
CVE-2023-50269 SQUID-2023:10 Denial of Service in HTTP Request parsing CWE-674 8.6 High 2023-12-14
CVE-2023-49285 Denial of Service in HTTP Message Processing in Squid CWE-126 8.6 High 2023-12-04
CVE-2023-49286 Denial of Service in Helper Process management CWE-617 8.6 High 2023-12-04
CVE-2023-49288 Denial of Service in HTTP Collapsed Forwarding in Squid CWE-416 8.6 High 2023-12-04
CVE-2023-46728 SQUID-2021:8 Denial of Service in Gopher gateway CWE-476 7.5 High 2023-11-06
CVE-2023-46724 SQUID-2023:4 Denial of Service in SSL Certificate validation CWE-125 8.6 High 2023-11-01

All 18 known CVE vulnerabilities affecting squid with full Chinese analysis, references, and POCs where available.