CVE-2026-47729

Published Jul 16, 2026

Last updated 7 days ago

Overview

Description
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
Source
security-advisories@github.com
NVD status
Analyzed
Products
squid

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

security-advisories@github.com
CWE-125

Social media

Hype score
Not currently trending
  1. CVE-2026-47729. Source: X search for CVE-2026 critical Posted: 2026-07-01T17:04:30.000Z Likes: 11

    @lyrie_ai

    20 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-47729. Source: X search for CVE-2026 critical Posted: 2026-06-24T16:07:18.000Z Likes: 11

    @lyrie_ai

    16 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2026-47729: Not every critical vuln leads to RCE. Sometimes it leaks the credentials that lead to one. Rapid Response test now available for Squidbleed (CVE-2026-47729).

    @lyrie_ai

    16 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 SQUIDBLEED ALERT (CVE-2026-47729) 🚨 https://t.co/UkJEtWVj62

    @ads_sivathiya

    23 Jun 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-47729 – Squidbleed 🦑 Heartbleed's ancient cousin, hiding in Squid since 1997 💀 https://t.co/1BIKrxsnPy #Squidbleed https://t.co/1BWYAdsuWH

    @0xBlackash

    22 Jun 2026

    11 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. 2 CVEs in Squid https://t.co/wpCWKt89Sz CVE-2026-47729: Out-of-Bounds Read from random unrelated transactions when accessing a misbehaving FTP server CVE-2026-50012: Heap-based Buffer Overflow when sending maliciously crafted replies to cache_digest request messages, fixed in 7.6

    @oss_security

    18 Jun 2026

    303 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. プロキシサーバーSquid がFTPゲートウェイの境界外読み取り(CVE-2026-47729)とcache_digestのヒープバッファオーバーフロー(CVE-2026-50012)の脆弱性を修正 https://t.co/mie3ulqIJp #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    17 Jun 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Squid 7.6 patches two memory bugs: CVE-2026-47729, an out-of-bounds read in the FTP gateway triggered by a misbehaving upstream FTP server, and CVE-2026-50012, a heap overflow in cache digests on --enable-cache-digests builds. If your proxy still gateways FTP, why is it still on?

    @canartuc

    15 Jun 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 脆弱性についての正式発表はまだだが、6/7にリリースされたSquidのv7.6で修正された脆弱性2件の情報が解禁。 oss-sec: Squid CVE-2026-47729 and CVE-2026-50012 https://t.co/4w1lTsJx5Q

    @autumn_good_35

    15 Jun 2026

    380 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations