SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NRed Hat Enterprise Linux
OSRedhat8.09.0Red Hat Enterprise Linux Eus
OSRedhat8.68.89.09.2Red Hat Enterprise Linux For Arm 64
OSRedhat8.0_aarch64Red Hat Enterprise Linux For IBM Z Systems
OSRedhat8.0_s390xRed Hat Enterprise Linux For Power Little Endian
OSRedhat8.0_ppc64leRed Hat Enterprise Linux Server Aus
OSRedhat8.28.48.69.2Red Hat Enterprise Linux Server Tus
OSRedhat8.28.48.68.89.2Squid Cache Squid
APPSquid-Cache2.6 – 6.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Firewall
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-5544CRITICAL9.8⚠ KEVPL ✓same product
Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS
CVE-2018-14667CRITICAL9.8⚠ KEVPL ✓same product
RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX