Briefing

Squidbleed: Heap Over-Read Vulnerability Exposes Cleartext HTTP Requests

security
by [email protected] (The Hacker News) ·

Patch Squid to a version that fixes the Squidbleed heap over‑read vulnerability.

What to do now

Patch Squid to a version that fixes the Squidbleed heap over‑read vulnerability.

Summary

A heap over‑read flaw in the Squid web proxy, dubbed Squidbleed, can leak another user’s cleartext HTTP request, including credentials and session tokens.

The bug originates from a 1997 FTP‑parsing change that remains active in Squid’s default configuration.

Researchers at Calif.io disclosed the vulnerability in June, highlighting its potential to expose sensitive data.

Squidbleed allows an attacker who can send traffic through the proxy to read the requests of other users.

The flaw is a classic information‑exposure vulnerability that could be exploited in shared proxy environments.

Security teams should patch Squid to a version that fixes the heap over‑read before it is exploited.

The discovery underscores the importance of keeping proxy software up to date.

Key changes

  • Heap over‑read in Squid can leak cleartext HTTP requests
  • Includes credentials or session tokens
  • Bug traces to 1997 FTP‑parsing change
  • Still live in default configuration
  • Disclosed in June, named Squidbleed

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting