National Cyber Warfare Foundation (NCWF)

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests


0 user ratings
2026-06-22 14:36:08
milo
Red Team (CNA) , Attacks
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.

The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed (



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.