CVE Tools
Back to feed
Research Squid Proxy info-disclosure Squid Cache Calif.io

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

SecurityWeek·By Eduard Kovacs··2 min read
CVE Tools coverage

Calif.io researchers reported a long-standing memory leak issue in Squid Proxy, tracked as CVE-2026-47729, affecting the FTP handling logic dating back to 1997. By manipulating an attacker-controlled FTP server, the proxy can read past a memory buffer and potentially disclose remnants of prior users’ uncleared HTTP requests, which is especially concerning in shared proxy deployments (e.g., corporate networks, schools, and public Wi‑Fi). While the impact is mainly limited to cleartext HTTP scenarios where Squid terminates TLS, sensitive credentials and session data may still be exposed without detection.