CVE-2026-47729
published 2026-07-16CVE-2026-47729: Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway…
PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.50%
72.4th percentile
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| squid-cache | squid | < 7.6 | 7.6 |
| squid | squid | — | — |
| squid_4 | squid | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
squid: memory disclosure in FTP gateway
vendor_redhat·2026-06-23·CVSS 6.5
CVE-2026-47729 [MEDIUM] CWE-125 squid: memory disclosure in FTP gateway
squid: memory disclosure in FTP gateway
A flaw was found in Squid. Due to improper input validation, an out-of-bounds read can occur in the FTP gateway. This issue allows an authenticated and trusted client to read memory from random transactions when accessing a misbehaving FTP server using the Squid gateway feature.
Statement: To exploit this issue, an attacker must have a valid account on the Squid proxy and must also control an FTP server reachable from the proxy on port 21. HTTPS traffic handled via CONNECT tunnels (the vast majority of modern web traffic) is opaque to the proxy because the underlying request data is encrypted and Squid does not have access to it. The impact is limited to information disclosure of cleartext HTTP request contents or traffic in TLS-terminating (SSL bu
VulDB
squid-cache Squid FTP Gateway out-of-bounds
vuldb·2026-06-12
CVE-2026-47729 [LOW] squid-cache Squid FTP Gateway out-of-bounds
A vulnerability was found in squid-cache Squid and classified as problematic. Affected by this issue is some unknown functionality of the component FTP Gateway Handler. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-47729. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-47729 squid: memory disclosure in FTP gateway [fedora-all]
bugzilla·2026-06-25
CVE-2026-47729 [MEDIUM] CVE-2026-47729 squid: memory disclosure in FTP gateway [fedora-all]
CVE-2026-47729 squid: memory disclosure in FTP gateway [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-47729 clustal-omega: memory disclosure in FTP gateway [fedora-all]
bugzilla·2026-06-25
CVE-2026-47729 [MEDIUM] CVE-2026-47729 clustal-omega: memory disclosure in FTP gateway [fedora-all]
CVE-2026-47729 clustal-omega: memory disclosure in FTP gateway [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-47729 squid: memory disclosure in FTP gateway
bugzilla·2026-06-25
CVE-2026-47729 [MEDIUM] CVE-2026-47729 squid: memory disclosure in FTP gateway
CVE-2026-47729 squid: memory disclosure in FTP gateway
Due to a improper validation of syntactic correctness of input bug, Squid is vulnerable to a out-of-bounds read attack against the FTP gateway.
This problem allows a trusted client to perform an out-of-bounds read from random unrelated transactions when accessing a misbehaving FTP server through Squid's gateway feature.
Hackernews
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
blogs_hackernews·2026-06-29·CVSS 8.8
CVE-2026-43503 [HIGH] ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.
The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting.
Here’s the full Monday recap.
## ⚡ Threat of the Week
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — Cybersecurity researchers detailed a new variant of the Dirty Frag Linux kernel flaw. Called DirtyClone (
Hackernews
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
blogs_hackernews·2026-06-23
CVE-2026-47729 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month.
Calling GPT‑5.5‑Cyber its "strongest model yet for finding and helping patch software vulnerabilities," OpenAI said the model can "sustain deeper analysis across large codebases" to identify security issues, validate them in a controlled environment, and develop and test patches.
In tandem, the tech upstart is releasing an update to the Codex S
Hackernews
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
blogs_hackernews·2026-06-22
CVE-2026-47729 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.
The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed ( CVE-2026-47729 ), after Heartbleed, which leaked memory the same way.
Squid describes this as an attack by a trusted client : someone already permitted to use the proxy, not any ra
https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8https://github.com/squid-cache/squid/pull/2408https://github.com/squid-cache/squid/pull/2409https://github.com/squid-cache/squid/releases/tag/SQUID_7_6https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg
2026-07-16
Published