
[CIVN-2026-0337] Information Disclosure Vulnerability in Squid Proxy
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Information Disclosure Vulnerability in Squid Proxy
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Squid versions older than 3.5.28
All Squid 4.x versions
All Squid 5.x versions
All Squid 6.x versions
All Squid 7.x versions up to and including 7.5
Overview
A vulnerability has been reported in Squid Proxy which could allow a trusted client to disclose sensitive information from unrelated transactions processed by the affected proxy.
Target Audience:
All organizations and individuals using affected versions of Squid Proxy.
Risk Assessment:
High risk of sensitive information disclosure and unauthorized access to user data.
Impact Assessment:
Potential for disclosure of sensitive information, including authentication credentials, session tokens and other HTTP request data.
Description
Squid Proxy is a widely used open-source web proxy and caching server that supports protocols such as HTTP, HTTPS and FTP to improve network performance and reduce bandwidth usage.
This vulnerability has been reported in Squid Proxy due to improper validation of syntactic correctness of input, resulting in an out-of-bounds read vulnerability in the FTP gateway feature. A trusted client could exploit this vulnerability by accessing a specially crafted or misbehaving FTP server through Squids FTP gateway.
Successful exploitation of this vulnerability could allow an attacker to disclose sensitive information from unrelated transactions processed by the affected proxy.
Solution
Apply appropriate updates as mentioned as mentioned by the Vendor:
https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg
Vendor Information
Squid Proxy
http://www.squid-cache.org/Advisories/
References
https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg
CVE Name
CVE-2026-47729
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo77i4ACgkQ3jCgcSdc
ys/7sxAAltwYuEKHvrXM22nM+cdSaXgQEAxg3tyOazd6WoXY8VQOrjESBRNmLmsx
Dke+i73WB++tRNpK3RPhx2D4qKnQY02aDNY7J/kkS8toZvRyXw0XAK0BKUDzvBON
e7U+bTiAS/1yBg1OOrmQOJlTc5Qvy/y4Jvx6oq/VS8gqxCALKlgAIYJAz2kmp4np
gWHz4c7H//AbgeSN32Arll++SxJYFKT3NYZNuCzRYOcD5w/kc2EHnemCnzKvkYEC
9PHWWlSvedixsjjtCnhHVsEYVnCWPehYg8IstL5U9tQvAt1WgWgo31Qv1JHd0gO7
jjH2VBsORtsbaNPngGPWQ0iXr/xAcJE7pFel2R2L7YiOCDgYtNWpaGW9riGyTaVC
fiTNKCeCbk87DLgchw9BH5O0zFETDo/+3PR3CFRqvKDmtqF2ap+7Iaf3GxhurvbX
kOEYb5WMo0dZofp1yRQNBT7p5fU2Wd5H8pWW03n7/hCRNDPioHRY9QB+qmrvCLlS
ThhkO9/G0C2ZckMbkpAsczcsMu+s+OOaNGbq+bJaidb+fp1KfjA+pGb1LP/WxAhn
yyXW6zDJ25ybAsPOvia6V3TDv74AwJLqx8p8IxPEdBNNE4z1pMv2mSLpKK4nYSNz
l7oQHUcX3ObcJXQQA2xKL8VnsbI76SJbl09CV1B6ZolrZoTKreo=
=BLAx
—–END PGP SIGNATURE—–


