- Description
- Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- squid
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-125
- Hype score
- Not currently trending
CVE-2026-47729. Source: X search for CVE-2026 critical Posted: 2026-07-01T17:04:30.000Z Likes: 11
@lyrie_ai
20 Jul 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-47729. Source: X search for CVE-2026 critical Posted: 2026-06-24T16:07:18.000Z Likes: 11
@lyrie_ai
16 Jul 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-47729: Not every critical vuln leads to RCE. Sometimes it leaks the credentials that lead to one. Rapid Response test now available for Squidbleed (CVE-2026-47729).
@lyrie_ai
16 Jul 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 SQUIDBLEED ALERT (CVE-2026-47729) 🚨 https://t.co/UkJEtWVj62
@ads_sivathiya
23 Jun 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-47729 – Squidbleed 🦑 Heartbleed's ancient cousin, hiding in Squid since 1997 💀 https://t.co/1BIKrxsnPy #Squidbleed https://t.co/1BWYAdsuWH
@0xBlackash
22 Jun 2026
11 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
2 CVEs in Squid https://t.co/wpCWKt89Sz CVE-2026-47729: Out-of-Bounds Read from random unrelated transactions when accessing a misbehaving FTP server CVE-2026-50012: Heap-based Buffer Overflow when sending maliciously crafted replies to cache_digest request messages, fixed in 7.6
@oss_security
18 Jun 2026
303 Impressions
2 Retweets
5 Likes
0 Bookmarks
0 Replies
0 Quotes
プロキシサーバーSquid がFTPゲートウェイの境界外読み取り(CVE-2026-47729)とcache_digestのヒープバッファオーバーフロー(CVE-2026-50012)の脆弱性を修正 https://t.co/mie3ulqIJp #セキュリティ対策Lab #security #securitynews
@securityLab_jp
17 Jun 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Squid 7.6 patches two memory bugs: CVE-2026-47729, an out-of-bounds read in the FTP gateway triggered by a misbehaving upstream FTP server, and CVE-2026-50012, a heap overflow in cache digests on --enable-cache-digests builds. If your proxy still gateways FTP, why is it still on?
@canartuc
15 Jun 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
脆弱性についての正式発表はまだだが、6/7にリリースされたSquidのv7.6で修正された脆弱性2件の情報が解禁。 oss-sec: Squid CVE-2026-47729 and CVE-2026-50012 https://t.co/4w1lTsJx5Q
@autumn_good_35
15 Jun 2026
380 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D1EAA421-658A-4C10-A77B-EA9D38A3EFB8",
"versionEndExcluding": "7.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]