29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
PoC publicSquid web proxyOur summary
A heap over-read in the Squid web proxy can expose another user’s cleartext HTTP request, potentially including credentials or session tokens, to attackers who already have permission to use the same proxy. The issue, called Squidbleed, is tracked as CVE-2026-47729 and is reported to affect Squid’s default configuration, with the attack requiring access patterns tied to Squid’s FTP parsing (including an FTP server on port 21). This matters because it can break confidentiality in shared proxy environments such as offices, schools, and public Wi‑Fi; however, HTTPS traffic behind CONNECT remains opaque to Squid.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.