CVE-2025-62168Information Exposure via Error Message in Squid

Severity
7.5HIGHNVD
CNA10.0
EPSS
0.2%
top 62.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Latest updateOct 28

Description

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Sq

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5squid-cache/squid< 7.2
Debiansquid/squid< 4.13-10+deb11u6+3

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-62168: Squid is a caching proxy for the Web2025-10-17
CVEList
Squid vulnerable to information disclosure via authentication credential leakage in error handling2025-10-17

📋Vendor Advisories

4
Ubuntu
Squid vulnerability2025-10-28
Red Hat
squid-cache: Squid vulnerable to information disclosure via authentication credential leakage in error handling2025-10-17
Microsoft
Squid vulnerable to information disclosure via authentication credential leakage in error handling2025-10-14
Debian
CVE-2025-62168: squid - Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure ...2025