PT-2026-49605 · Unknown+4 · Squid Proxy+4

CVE-2026-47729

·

Published

2026-04-17

·

Updated

2026-09-01

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Squid versions prior to 7.6
Description An out-of-bounds read exists in the FTP gateway due to improper validation of input syntactic correctness within the src/clients/FtpGateway.cc file. When a listing entry date in TypeA or TypeB directory-listing formats is not followed by a filename, the parsing process is not restricted to the input buffer. This allows a trusted client accessing a misbehaving FTP server through the gateway to read memory from random unrelated transactions, potentially leaking cleartext HTTP requests, including authentication credentials, session tokens, and API keys from other users. The root cause is related to the behavior of the strchr() function regarding null terminators in C. This issue, dubbed Squidbleed, affects the default configuration and has existed since a 1997 code change.
Recommendations Update Squid to version 7.6 or later. Disable FTP support entirely to remove the attack surface.

Exploit

Fix

RCE

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92444
BDU:2026-08611
CVE-2026-47729
GHSA-8C37-PXJQ-QWRG
OESA-2026-2726
USN-8435-1

Affected Products

Linuxmint
Red Os
Squid Cache
Squid Proxy
Ubuntu