PT-2026-49605 · Unknown+4 · Squid Proxy+4
CVE-2026-47729
·
Published
2026-04-17
·
Updated
2026-09-01
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 7.6
Description
An out-of-bounds read exists in the FTP gateway due to improper validation of input syntactic correctness within the
src/clients/FtpGateway.cc file. When a listing entry date in TypeA or TypeB directory-listing formats is not followed by a filename, the parsing process is not restricted to the input buffer. This allows a trusted client accessing a misbehaving FTP server through the gateway to read memory from random unrelated transactions, potentially leaking cleartext HTTP requests, including authentication credentials, session tokens, and API keys from other users. The root cause is related to the behavior of the strchr() function regarding null terminators in C. This issue, dubbed Squidbleed, affects the default configuration and has existed since a 1997 code change.Recommendations
Update Squid to version 7.6 or later.
Disable FTP support entirely to remove the attack surface.
Exploit
Fix
RCE
DoS
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Squid Cache
Squid Proxy
Ubuntu