📦 Squid

by Squid Cache

🔍 What is Squid?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-62168

CRITICAL CVSS 10.0 Oct 17, 2025

Squid caching proxy versions before 7.2 fail to properly redact HTTP authentication credentials in error messages, allowing information disclosure. This vulnerability enables scripts to bypass browser...

CVE-2025-54574

CRITICAL CVSS 9.3 Aug 1, 2025

Squid caching proxy versions 6.3 and below contain a heap buffer overflow vulnerability in URN processing that could allow remote attackers to execute arbitrary code. This affects all systems running ...

CVE-2023-46846

CRITICAL CVSS 9.3 Nov 3, 2023

CVE-2023-46846 is an HTTP request smuggling vulnerability in Squid proxy due to lenient chunked decoder handling. It allows attackers to bypass security controls like firewalls and frontend systems by...

CVE-2024-45802

HIGH CVSS 7.5 Oct 28, 2024

This vulnerability in Squid proxy allows trusted servers to cause denial of service against all clients using the proxy through resource management flaws. It affects Squid installations where the prox...

CVE-2024-25111

HIGH CVSS 8.6 Mar 6, 2024

CVE-2024-25111 is an uncontrolled recursion vulnerability in Squid's HTTP chunked decoder that allows remote attackers to cause denial of service by sending specially crafted chunked HTTP messages. Th...

CVE-2023-50269

HIGH CVSS 8.6 Dec 14, 2023

Squid caching proxy versions 2.6 through 6.5 contain an uncontrolled recursion vulnerability in HTTP request parsing when the follow_x_forwarded_for feature is enabled. Remote attackers can cause deni...

CVE-2023-49286

HIGH CVSS 8.6 Dec 4, 2023

Squid caching proxy versions before 6.5 contain an incorrect check of function return value bug in helper process management that allows denial of service attacks. Attackers can crash Squid's helper p...

CVE-2023-46848

HIGH CVSS 8.6 Nov 3, 2023

Squid proxy server is vulnerable to a denial-of-service attack where remote attackers can crash the service by sending specially crafted ftp:// URLs in HTTP requests or constructing them from FTP nati...

CVE-2023-5824

HIGH CVSS 7.5 Nov 3, 2023

A vulnerability in Squid proxy server allows cached HTTP response headers to exceed configured size limits, causing worker process stalls or crashes when retrieving large headers from disk cache. This...

CVE-2024-37894

MEDIUM CVSS 6.3 Jun 25, 2024

Squid caching proxy versions 6.0.1 through 6.9 and 5.0.5 through 5.9 are vulnerable to memory corruption due to an out-of-bounds write error when assigning ESI variables. This vulnerability can be exp...