CVE Tools

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

SecurityWeekBy Eduard Kovacs

ResearchSquid ProxySquid Cache

Our summary

Calif.io researchers reported a long-standing memory leak issue in Squid Proxy, tracked as CVE-2026-47729, affecting the FTP handling logic dating back to 1997. By manipulating an attacker-controlled FTP server, the proxy can read past a memory buffer and potentially disclose remnants of prior users’ uncleared HTTP requests, which is especially concerning in shared proxy deployments (e.g., corporate networks, schools, and public Wi‑Fi). While the impact is mainly limited to cleartext HTTP scenarios where Squid terminates TLS, sensitive credentials and session data may still be exposed without detection.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store