Debian Squid vulnerabilities
120 known vulnerabilities affecting debian/squid.
Total CVEs
120
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW17
Vulnerabilities
Page 2 of 6
CVE-2024-23638P3MEDIUMCVSS 6.5fixed in squid 5.7-2+deb12u1 (bookworm)2024
CVE-2024-23638 [MEDIUM] CVE-2024-23638: squid - Squid is a caching proxy for the Web. Due to an expired pointer reference bug, S...
Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be
debian
CVE-2016-4051P3HIGHCVSS 8.8fixed in squid 4.1-1 (bookworm)2016
CVE-2016-4051 [HIGH] CVE-2016-4051: squid - Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before ...
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4.1-1)
trixie:
debian
CVE-2019-12524P2CRITICALCVSS 9.8fixed in squid 4.8-1 (bookworm)2019
CVE-2019-12524 [CRITICAL] CVE-2019-12524: squid - An issue was discovered in Squid through 4.7. When handling requests from users,...
An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes
debian
CVE-2004-0189P3HIGHCVSS 7.5PoCfixed in squid 2.5.5-1 (bookworm)2004
CVE-2004-0189 [HIGH] CVE-2004-0189: squid - The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote at...
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
Scope: local
bookworm: resolved (fixed in 2.5.5-1)
bullseye: resolved (fixed in 2.5.5-1)
forky: resolved
debian
CVE-1999-0710P3HIGHCVSS 7.5PoCfixed in squid 2.5.7-1 (bookworm)1999
CVE-1999-0710 [HIGH] CVE-1999-0710: squid - The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, install...
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.7-1)
forky: resolved (fixed in 2.5.7-1)
sid: resolved (fixed in 2.5.7-1)
trixi
debian
CVE-2021-28662P3MEDIUMCVSS 6.5fixed in squid 4.13-10 (bookworm)2021
CVE-2021-28662 [MEDIUM] CVE-2021-28662: squid - An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remo...
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
Scope: local
bookworm: resolved (fixed in 4.13-10)
bullseye: resolved (fixed in 4.13-10)
forky: resolved (fixed in 4.13-10)
sid: resolved
debian
CVE-2019-12523P3CRITICALCVSS 9.1fixed in squid 4.9-1 (bookworm)2019
CVE-2019-12523 [CRITICAL] CVE-2019-12523: squid - An issue was discovered in Squid before 4.9. When handling a URN request, a corr...
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on lo
debian
CVE-2014-7141P3MEDIUMCVSS 6.4fixed in squid 4.1-1 (bookworm)2014
CVE-2014-7141 [MEDIUM] CVE-2014-7141: squid - The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive...
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4.1-1)
trixie: resol
debian
CVE-2019-13345P3MEDIUMCVSS 6.1fixed in squid 4.8-1 (bookworm)2019
CVE-2019-13345 [MEDIUM] CVE-2019-13345: squid - The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or au...
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
Scope: local
bookworm: resolved (fixed in 4.8-1)
bullseye: resolved (fixed in 4.8-1)
forky: resolved (fixed in 4.8-1)
sid: resolved (fixed in 4.8-1)
trixie: resolved (fixed in 4.8-1)
debian
CVE-2020-25097P3HIGHCVSS 8.6fixed in squid 4.13-8 (bookworm)2020
CVE-2020-25097 [HIGH] CVE-2020-25097: squid - An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to impr...
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
Scope: local
bookworm: resolved (fixed in 4.13-8)
bullseye: resolved (fixed i
debian
CVE-2015-5400P3MEDIUMCVSS 6.8fixed in squid 4.1-1 (bookworm)2015
CVE-2015-5400 [MEDIUM] CVE-2015-5400: squid - Squid before 3.5.6 does not properly handle CONNECT method peer responses when c...
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4
debian
CVE-2019-12519P3CRITICALCVSS 9.8fixed in squid 4.11-1 (bookworm)2019
CVE-2019-12519 [CRITICAL] CVE-2019-12519: squid - An issue was discovered in Squid through 4.7. When handling the tag esi:when whe...
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, t
debian
CVE-2020-15049P3CRITICALCVSS 9.9fixed in squid 4.12-1 (bookworm)2020
CVE-2020-15049 [CRITICAL] CVE-2020-15049: squid - An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12...
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
Scope: local
bookworm: resolv
debian
CVE-2005-0241P3MEDIUMCVSS 5.0fixed in squid 2.5.7-7 (bookworm)2005
CVE-2005-0241 [MEDIUM] CVE-2005-0241: squid - The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier ...
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
Scope: local
bookworm: resolved (fixed in 2.5.7-7)
bullseye: resolved (fixed in 2.5.7-7)
forky:
debian
CVE-2025-21311P3CRITICALCVSS 9.8fixed in squid 7.1-1 (forky)2025
CVE-2025-21311 [CRITICAL] CVE-2025-21311: squid - Windows NTLM V1 Elevation of Privilege Vulnerability
Windows NTLM V1 Elevation of Privilege Vulnerability
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 7.1-1)
sid: resolved (fixed in 7.1-1)
trixie: open
debian
CVE-2026-33526P3CRITICALCVSS 9.2fixed in squid 7.5-1 (forky)2026
CVE-2026-33526 [CRITICAL] CVE-2026-33526: squid - Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-Afte...
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enab
debian
CVE-2020-8449P3HIGHCVSS 7.5fixed in squid 4.10-1 (bookworm)2020
CVE-2020-8449 [HIGH] CVE-2020-8449: squid - An issue was discovered in Squid before 4.10. Due to incorrect input validation,...
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
Scope: local
bookworm: resolved (fixed in 4.10-1)
bullseye: resolved (fixed in 4.10-1)
forky: resolved (fixed in 4.10-1)
sid: resolved (fixed in 4.10-1)
trixie: resol
debian
CVE-2005-0173P3HIGHCVSS 7.5fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0173 [HIGH] CVE-2005-0173: squid - squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to by...
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
Scope: local
bookworm: resolved (fixed in 2.5.7-4)
bullseye: resolved (fixed in 2.5.7-4)
forky: resolved (fixed in 2.5.7-4)
sid: resolved (fixed in 2.5.7-
debian
CVE-2026-32748P3HIGHCVSS 8.7fixed in squid 7.5-1 (forky)2026
CVE-2026-32748 [HIGH] CVE-2026-32748: squid - Squid is a caching proxy for the Web. Prior to version 7.5, due to premature rel...
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This
debian
CVE-2007-0247P4LOWCVSS 5.0PoCfixed in squid 2.6.5-4 (bookworm)2007
CVE-2007-0247 [MEDIUM] CVE-2007-0247: squid - squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a...
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.
Scope: local
bookworm: resolved (fixed in 2.6.5-4)
bullseye: resolved (fixed in 2.6.5-4)
forky: resolved (fixed in 2.6.5-4)
sid: r
debian