Three Squid proxy vulnerabilities expose networks to request smuggling and stack buffer overflow attacks. Network administrators must immediately patch their caching servers to prevent unauthorized cache poisoning and out-of-bounds writes.
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Squid operates as a widely deployed caching proxy for web traffic. Industry estimates indicate that thousands of enterprise networks rely on it to accelerate content delivery. Consequently, unpatched Squid proxy vulnerabilities expose internal corporate infrastructure to severe risks. If attackers exploit these flaws, they can poison web caches and distribute malicious content to unsuspecting clients.
How the Attacks Work
The first vulnerability, tracked as CVE-2026-61642, involves improper enforcement of behavioral workflows. Specifically, attackers exploit HTTP/1.1 Transfer-Encoding to launch request smuggling attacks. This action allows trusted clients to bypass security mechanisms and store arbitrary malicious payloads within the web cache.
Additionally, SQUID-2026:8 and SQUID-2026:7 introduce stack-based buffer overflows due to improper input validation. Under SQUID-2026:8, attackers use an external ACL helper to perform an out-of-bounds write. They achieve this by passing excessively long user and password annotations during ICAP authentication. Similarly, SQUID-2026:7 allows trusted clients to trigger an out-of-bounds write during basic HTTP authentication with a peer server. Currently, security researchers confirm no active in-the-wild exploitation or public proof-of-concept for these flaws.
Affected Versions
These security flaws impact multiple Squid proxy deployments. The request smuggling vulnerability affects versions 3.3.0.1 through 7.5. Both buffer overflow vulnerabilities impact versions 3.0 through 7.7.
Patch and Mitigation Steps
Administrators must update their deployments promptly to protect their environments. The development team resolved the HTTP smuggling flaw in version 7.6. Meanwhile, the buffer overflows received official fixes in version 7.7. If immediate upgrades are impossible, network engineers can implement temporary mitigations. For instance, teams can restrict the length of allowed usernames or use alternate authentication methods. You can find official patches and detailed technical guidance on the Squid security advisories repository.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!