CVE-2026-50012
published 2026-07-16CVE-2026-50012: Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in…
PriorityP335medium5.5CVSS 3.1
AVNACLPRHUINSUCNILAH
EPSS
1.36%
69.7th percentile
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| squid-cache | squid | < 7.6 | 7.6 |
| squid | squid | — | — |
| squid_4 | squid | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
squid-cache Squid Cache Digest heap-based overflow
vuldb·2026-06-12
CVE-2026-50012 [CRITICAL] squid-cache Squid Cache Digest heap-based overflow
A vulnerability was found in squid-cache Squid. It has been classified as critical. This affects an unknown part of the component Cache Digest Handler. This manipulation causes heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-50012. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
Red Hat
squid: memory corruption in cache_digest reply handling
vendor_redhat·2026-06-23·CVSS 5.5
CVE-2026-50012 [MEDIUM] CWE-122 squid: memory corruption in cache_digest reply handling
squid: memory corruption in cache_digest reply handling
A flaw was found in Squid. Due to improper input validation, a heap-based buffer overflow can occur when processing cache digests. This issue allows a trusted server to cause a denial of service when sending specially crafted replies to cache_digest request messages.
Statement: To exploit this issue, an attacker must control a trusted cache peer server. Also, cache digests are not enabled in the default configuration. Squid deployments that do not use cache peering are not affected. Furthermore, even those that do are only vulnerable when the attacker controls a configured peer server within the same administrative domain. A compromised peer can reliably crash the Squid process via a heap-based buffer overflow during digest exchange
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-50012 squid: memory corruption in cache_digest reply handling [fedora-all]
bugzilla·2026-06-25
CVE-2026-50012 [MEDIUM] CVE-2026-50012 squid: memory corruption in cache_digest reply handling [fedora-all]
CVE-2026-50012 squid: memory corruption in cache_digest reply handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-50012 clustal-omega: memory corruption in cache_digest reply handling [fedora-all]
bugzilla·2026-06-25
CVE-2026-50012 [MEDIUM] CVE-2026-50012 clustal-omega: memory corruption in cache_digest reply handling [fedora-all]
CVE-2026-50012 clustal-omega: memory corruption in cache_digest reply handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-50012 squid: memory corruption in cache_digest reply handling
bugzilla·2026-06-25
CVE-2026-50012 [MEDIUM] CVE-2026-50012 squid: memory corruption in cache_digest reply handling
CVE-2026-50012 squid: memory corruption in cache_digest reply handling
Due to an improper input validation bug, Squid is vulnerable to a heap-based buffer overflow attack against cache digests.
This problem allows a trusted server to perform a heap-based buffer overflow when sending maliciously crafted replies to cache_digest request messages.
This attack is limited to Squid instances that have been compiled with the --enable-cache-digests option. Trusted peers are expected to be servers within the same administrative domain. As cache digests are exchanged over TCP, there is no risk of spoofing.
Hackernews
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
blogs_hackernews·2026-06-22
CVE-2026-47729 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.
The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed ( CVE-2026-47729 ), after Heartbleed, which leaked memory the same way.
Squid describes this as an attack by a trusted client : someone already permitted to use the proxy, not any ra
2026-07-16
Published