Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Summary
Security researchers disclosed a long-standing memory leak flaw in Squid Proxy that can expose user data in shared proxy environments. The issue, dubbed Squidbleed, can let an attacker read uncleared HTTP request data and potentially capture credentials, session tokens, and API keys. The risk mainly affects cleartext HTTP traffic and deployments where Squid terminates TLS, while standard HTTPS Connect tunnels remain unaffected. A patch already exists in Squid 7.6 and Squid 8, and operators can reduce exposure further by disabling FTP support if they do not need it.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected