Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Squid MEDIUM 6.5
CVE-2026-47729

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/F…

Fix: 7.6+
Fix from $1,600 2026-07-16
Squid MEDIUM 5.5
CVE-2026-50012

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in s…

Fix: 7.6+
Fix from $1,600 2026-07-16
Squid HIGH 7.5
CVE-2026-33526EPSS 9%

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP tr…

Fix: 7.5+
Fix from $1,950 2026-03-26
Squid MEDIUM 6.5
CVE-2026-33515

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling…

Fix: 7.5+
Fix from $1,600 2026-03-26
Squid HIGH 7.5
CVE-2026-32748EPSS 9%

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bug…

Fix: 7.5+
Fix from $1,950 2026-03-26
Squid HIGH 7.5
CVE-2025-62168EPSS 63%

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows in…

Fix: 7.2+
Fix from $1,950 2025-10-17
Squid CRITICAL 9.8
CVE-2025-54574EPSS 23%

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution att…

Fix: 6.4+
Fix from $2,300 2025-08-01
Squid HIGH 7.5
CVE-2024-45802EPSS 48%

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource Durin…

Fix: 6.10+
Fix from $1,950 2024-10-28
Squid MEDIUM 6.3
CVE-2024-37894EPSS 6%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid i…

Fix: 6.10+
Fix from $1,600 2024-06-25
Squid HIGH 7.5
CVE-2024-25617EPSS 89%

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may b…

Fix: 6.5+
Fix from $1,950 2024-02-14
Squid MEDIUM 6.5
CVE-2024-23638EPSS 60%

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack…

Fix: 6.6+
Fix from $1,600 2024-01-24
Squid HIGH 7.5
CVE-2023-50269EPSS 58%

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and version…

Fix: after 6.5
Fix from $1,950 2023-12-14
Squid HIGH 7.5
CVE-2023-49285EPSS 89%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service a…

Fix: after 6.4
Fix from $1,950 2023-12-04
Squid HIGH 7.5
CVE-2023-49286EPSS 10%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerabl…

Fix: after 6.4
Fix from $1,950 2023-12-04
Squid HIGH 7.5
CVE-2023-49288

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which ca…

Fix: after 5.9
Fix from $1,950 2023-12-04
Squid HIGH 7.5
CVE-2023-46728EPSS 6%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of …

Fix: 6.0.1+
Fix from $1,950 2023-11-06
Squid HIGH 7.5
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 c…

Fix: 6.4+
Fix from $1,950 2023-11-01
Squid HIGH 8.6
CVE-2022-41318

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authenticat…

Fix: 5.7+
Fix from $1,950 2022-12-25
Squid MEDIUM 6.5
CVE-2022-41317

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sens…

Fix: 5.7+
Fix from $1,600 2022-12-25
Squid MEDIUM 6.5
CVE-2020-14059

An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an S…

Fix: 5.0.3+
Fix from $1,600 2020-06-30
Squid MEDIUM 6.1
CVE-2018-19131

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

Fix: 4.4+
Fix from $1,600 2018-11-09
Squid MEDIUM 5.9
CVE-2018-1172EPSS 9%

This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authen…

Mitigation only
Fix from $1,600 2018-05-16
Squid HIGH 7.5
CVE-2016-10003

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature…

Fix: 3.5.23 / 4.0.17+
Fix from $1,950 2017-01-27
Squid MEDIUM 5.9
CVE-2016-2390EPSS 26%

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when …

Fix: after 3.5.13
Fix from $1,600 2016-04-19
Squid HIGH 7.5
CVE-2016-3948EPSS 35%

Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a cra…

Patch available
Fix from $1,950 2016-04-07
Squid HIGH 7.5
CVE-2016-2572EPSS 10%

http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2571EPSS 9%

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remo…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2570EPSS 9%

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows rem…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2569EPSS 31%

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of servic…

Patch available
Fix from $1,950 2016-02-27
Squid MEDIUM 6.4
CVE-2014-7141EPSS 76%

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and cra…

Patch available
Fix from $1,600 2014-11-26