Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

General News

Summary

Security researchers disclosed a long-standing memory leak flaw in Squid Proxy that can expose user data in shared proxy environments. The issue, dubbed Squidbleed, can let an attacker read uncleared HTTP request data and potentially capture credentials, session tokens, and API keys. The risk mainly affects cleartext HTTP traffic and deployments where Squid terminates TLS, while standard HTTPS Connect tunnels remain unaffected. A patch already exists in Squid 7.6 and Squid 8, and operators can reduce exposure further by disabling FTP support if they do not need it.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
No AI classifications detected

Linked Companies