From squid3 at treenet.co.nz Sat Sep 12 02:55:17 2026 From: squid3 at treenet.co.nz (Amos Jeffries) Date: Sat, 12 Sep 2026 14:55:17 +1200 Subject: [squid-announce] [ADVISORY] SQUID-2026:9 FTP command injection in FTP gateway Message-ID: <4302f9cf-ec41-4db6-a0df-521eae59e762@treenet.co.nz> __________________________________________________________________ Squid Proxy Cache Security Update Advisory SQUID-2026:9 __________________________________________________________________ Advisory ID: | SQUID-2026:9 Date: | 2026-07-05 Summary: | FTP command injection in FTP gateway Affected versions: | Squid 2.x -> 2.7.STABLE9 | Squid 3.x -> 3.5.28 | Squid 4.x -> 4.17 | Squid 5.x -> 5.9 | Squid 6.x -> 6.14 | Squid 7.x -> 7.6 Fixed in version: | Squid 7.7 __________________________________________________________________ Problem Description: Due to a Improper Validation of Syntactic Correctness bug Squid is vulnerable to a Command Injection attack against FTP Gateway. __________________________________________________________________ Severity: This problem allows a trusted client to perform Command Injection when accessing an ftp:// URL. Allowing the client access to files, directories and features of the FTP server normally forbidden by Squid security policy. __________________________________________________________________ Updated Packages: This bug is fixed by Squid version 7.7. In addition, patches addressing this problem for the stable releases can be found in our patch archives: Squid 7: If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages. __________________________________________________________________ Determining if your version is vulnerable: Squid older than 5.0 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.14 are vulnerable. All Squid-7.x up to and including 7.6 are vulnerable. __________________________________________________________________ Workaround: Forbid access to FTP Gateway by placing the below settings before any "http_access allow" lines in squid.conf: acl FTP proto FTP http_access deny FTP Also, remove from squid.conf the line: acl Safe_ports port 21 __________________________________________________________________ Contact details for the Squid project: For installation / upgrade support on binary packaged versions of Squid: Your first point of contact should be your binary package vendor. If you install and build Squid from the original Squid sources then the mailing list is your primary support point. For subscription details see . For reporting of non-security bugs in the latest STABLE release the squid bugzilla database should be used . For reporting of security sensitive bugs send an email to the mailing list. It's a closed list (though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __________________________________________________________________ Credits: This vulnerability was discovered independently by David Fifield, and Pavel Kohout of Aisle Research, and Ajith Prabhu Fixed by Ricardo Ferreira Ribeiro of Open Systems AG in collaboration with The Measurement Factory. __________________________________________________________________ Revision history: 2019-06-21 00:00:52 UTC Initial Report by David Fifield 2026-03-02 19:38:00 UTC Report by Ajith Prabhu 2026-03-04 12:41:54 UTC Report by Pavel Kohout of Aisle Research __________________________________________________________________ END From squid3 at treenet.co.nz Sat Sep 12 03:13:38 2026 From: squid3 at treenet.co.nz (Amos Jeffries) Date: Sat, 12 Sep 2026 15:13:38 +1200 Subject: [squid-announce] [ADVISORY] SQUID-2026:6 Request Smuggling in HTTP Transfer-Encoding Message-ID: __________________________________________________________________ Squid Proxy Cache Security Update Advisory SQUID-2026:6 __________________________________________________________________ Advisory ID: | SQUID-2026:6 Date: | 2026-06-23 Summary: | Request Smuggling in HTTP Transfer-Encoding Affected versions: | Squid 3.3 -> 3.5.28 | Squid 4.x -> 4.17 | Squid 5.x -> 5.9 | Squid 6.x -> 6.14 | Squid 7.x -> 7.5 Fixed in version: | Squid 7.6 __________________________________________________________________ Problem Description: Due to a CWE-841 Improper Enforcement of Behavioral Workflow bug Squid is vulnerable to a Request Smuggling attack against HTTP/1.1 Transfer-Encoding. __________________________________________________________________ Severity: This problem allows a trusted client to perform an HTTP Request Smuggling attack when HTTP/1.1 is used. Bypassing security mechanisms that may be in place between attacker and Squid. When there is an HTTP cache operating prior to the affected Squid, this Request Smuggling attack also allows the attacker to poison that web cache and store arbitrary malicious content at any URL for delivery to other clients future requests. __________________________________________________________________ Updated Packages: This bug is fixed by Squid version 7.6. In addition, patches addressing this problem for the stable releases can be found in our patch archives: Squid 7: If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages. __________________________________________________________________ Determining if your version is vulnerable: Squid older than 3.3 have not been tested and should be assumed to be not vulnerable. All Squid-3.3 up to and including 3.5.28 have not been tested and should be assumed to be vulnerable. All Squid-4.x up to and including 4.17 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 have not been tested and should be assumed to be vulnerable. All Squid-6.x up to and including 6.14 are vulnerable. All Squid-7.x up to and including 7.5 are vulnerable. __________________________________________________________________ Workaround: There is no workaround for these issues. __________________________________________________________________ Contact details for the Squid project: For installation / upgrade support on binary packaged versions of Squid: Your first point of contact should be your binary package vendor. If you install and build Squid from the original Squid sources then the mailing list is your primary support point. For subscription details see . For reporting of non-security bugs in the latest STABLE release the squid bugzilla database should be used . For reporting of security sensitive bugs send an email to the mailing list. It's a closed list (though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __________________________________________________________________ Credits: This vulnerability was discovered by Mitchell Benjamin, Revamp Studio. Fixed by Amos Jeffries , Treehouse Networks Ltd. __________________________________________________________________ Revision history: 2026-05-29 08:04:59 UTC Initial Report 2026-05-31 08:29:04 UTC Patch Released __________________________________________________________________ END From squid3 at treenet.co.nz Sat Sep 12 03:16:25 2026 From: squid3 at treenet.co.nz (Amos Jeffries) Date: Sat, 12 Sep 2026 15:16:25 +1200 Subject: [squid-announce] [ADVISORY] SQUID-2026:8 Stack Buffer Overflow in ICAP Authentication Message-ID: <7738761c-39aa-40de-8ac7-013d05237c6a@treenet.co.nz> __________________________________________________________________ Squid Proxy Cache Security Update Advisory SQUID-2026:8 __________________________________________________________________ Advisory ID: | SQUID-2026:8 Date: | 2026-08-25 Summary: | Stack Buffer Overflow in ICAP Authentication Affected versions: | Squid 3.x -> 3.5.28 | Squid 4.x -> 4.17 | Squid 5.x -> 5.9 | Squid 6.x -> 6.14 | Squid 7.x -> 7.6 Fixed in version: | Squid 7.7 __________________________________________________________________ Problem Description: Due to an Improper Input Validation (CWE-20) bug Squid is vulnerable to a Stack-based Buffer Overflow (CWE-121) when configured to use an ICAP Server in conjunction with a misbehaving external ACL authentication helper. __________________________________________________________________ Severity: This problem allows an external acl helper to perform an out-of-bounds write when passing credentials as user= and password= annotations for use by an ICAP Service. __________________________________________________________________ Updated Packages: This bug is fixed by Squid version 7.7 In addition, patches addressing this problem for the stable releases can be found in our patch archives: Squid 7: If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages. __________________________________________________________________ Determining if your version is vulnerable: Squid older than 3.5.28 have not been tested but should be considered vulnerable. All Squid-4.x up to and including 4.17 are not vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.14 are vulnerable. All Squid-7.x up to and including 7.6 are vulnerable. __________________________________________________________________ Workaround: If vulnerable external ACL programs get credentials from Squid transactions, exclude vulnerable external ACLs from seeing transactions that contain excessively long credentials. Wrap vulnerable external ACL helper programs into an output filtering program to prevent excessively long credentials from reaching Squid. __________________________________________________________________ Contact details for the Squid project: For installation / upgrade support on binary packaged versions of Squid: Your first point of contact should be your binary package vendor. If you install and build Squid from the original Squid sources then the mailing list is your primary support point. For subscription details see . For reporting of non-security bugs in the latest STABLE release the squid bugzilla database should be used . For reporting of security sensitive bugs send an email to the mailing list. It's a closed list (though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __________________________________________________________________ Credits: This vulnerability was discovered independently by: breakingbad6, Yingpei Zeng and Yanzhao Shen, and Hcamael Fixed by Francesco Chemolli <> __________________________________________________________________ Revision history: 2026-05-09 18:29:00 UTC Initial report 2026-06-23 07:00:00 UTC Patch published 2026-08-25 21:00:00 UTC Advisory drafted __________________________________________________________________ END From squid3 at treenet.co.nz Sat Sep 12 03:20:16 2026 From: squid3 at treenet.co.nz (Amos Jeffries) Date: Sat, 12 Sep 2026 15:20:16 +1200 Subject: [squid-announce] [ADVISORY] SQUID-2026:7 Stack Buffer Overflow in HTTP Authentication Message-ID: <05da3518-e056-4875-ae56-9e828dd2d890@treenet.co.nz> __________________________________________________________________ Squid Proxy Cache Security Update Advisory SQUID-2026:7 __________________________________________________________________ Advisory ID: | SQUID-2026:7 Date: | 2026-07-30 Summary: | Stack Buffer Overflow in HTTP Authentication Affected versions: | Squid 4.0.1 -> 4.17 | Squid 5.x -> 5.9 | Squid 6.x -> 6.14 | Squid 7.x -> 7.6 Fixed in version: | Squid 7.7 __________________________________________________________________ Problem Description: Due to an Improper Input Validation (CWE-20) bug Squid is vulnerable to a Stack-based Buffer Overflow (CWE-121) attack against HTTP Authentication. __________________________________________________________________ Severity: This problem allows a trusted client to perform an out-of-bounds write when squid is configured to authenticate with a peer server using client provided Basic authentication credentials. This attack is limited to squid deployments passing client supplied Basic authentication credentials to a cache_peer. __________________________________________________________________ Updated Packages: This bug is fixed by Squid version 7.7 In addition, patches addressing this problem for the stable releases can be found in our patch archives: Squid 7: If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages. __________________________________________________________________ Determining if your version is vulnerable: Squid older than 3.5.28 have not been tested but should be considered not vulnerable. All Squid-4.x up to and including 4.17 are not vulnerable. For Squid-5 and newer run the command: squid -k parse 2>&1 | \ grep -E "cache_peer.*login=(\*:|PASS)" || \ echo "not vulnerable" All Squid-5.x up to and including 5.9 are vulnerable when passing traffic to any cache_peer listed by the above command. All Squid-6.x up to and including 6.14 are vulnerable when passing traffic to any cache_peer listed by the above command. All Squid-7.x up to and including 7.6 are vulnerable when passing traffic to any cache_peer listed by the above command. __________________________________________________________________ Workaround: Among the possible workarounds: * Use a different form of authentication in the cache_peer such as for instance a src type ACL. * restrict the length of allowed usernames, for instance using: acl long_username proxy_auth_regex ^.{100,}$ http_access deny long_username_check __________________________________________________________________ Contact details for the Squid project: For installation / upgrade support on binary packaged versions of Squid: Your first point of contact should be your binary package vendor. If you install and build Squid from the original Squid sources then the mailing list is your primary support point. For subscription details see . For reporting of non-security bugs in the latest STABLE release the squid bugzilla database should be used . For reporting of security sensitive bugs send an email to the mailing list. It's a closed list (though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __________________________________________________________________ Credits: This vulnerability was discovered by: breakingbad6, Yingpei Zeng and Yanzhao Shen Fixed by Francesco Chemolli <> __________________________________________________________________ Revision history: 2026-05-09 18:29:00 UTC Initial report 2026-06-23 07:00:00 UTC Patch published 2026-08-09 21:00:00 UTC Advisory drafted __________________________________________________________________ END