CVE-2026-47729
Squid: Memory disclosure in FTP gateway
Description
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and Moreen·The Hacker News·
- Squidbleed (CVE-2026-47729): Squid Proxy Memory Leak Details and PoC Discloseden-us·Daily CyberSecurity (securityonline.info)· PoC Squid ics-ot-iot
- Уязвимость Squidbleed существовала в коде Squid 29 летru-ru·Хакер (xakep.ru)· PoC Squid info-disclosure
- OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flawsen·The Hacker News· Research ai-ml
- 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requestsen·The Hacker News· PoC Squid web proxy info-disclosure
- Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Dataen-us·SecurityWeek· Research Squid Proxy info-disclosure
- Critical Squid Proxy Vulnerabilities Patched in Latest Releaseen-us·Daily CyberSecurity (securityonline.info)· Patch Squid 7.6 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-47729 and every CVE in our database. Create a free account — no credit card required.
Create Free Account