securityonline.info 6/24/2026, 2:01:32 AM · external

Squid Proxy Flaw Exposes User Logins via FTP Parser Bug

Squid Proxy Flaw Exposes User Logins via FTP Parser Bug
Developing story vulnerability 4 articles tracked
Squid proxy vulnerabilities (CVE-2026-47729, CVE-2026-50012) patched
CyberSIXT Evidence Panel
Primary Source blog.calif.io
CISA KEV Not in KEV
Patch Patch Status Unknown

THE page details the critical Squidbleed vulnerability (CVE-2026-47729) affecting the Squid web proxy, which exposes user HTTP requests, including sensitive data like passwords and session tokens. Discovered by Calif.io, this issue has existed since 1997 and is significant for shared network environments where many users may be affected. The vulnerability arises from a flaw in Squid's FTP directory-listing parser, which can leak data when a specific exploit is used.

A fix has been implemented in later Squid versions, but affected users should also consider disabling FTP support to mitigate risks. The issue has a moderate CVSS score of 6.5.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline