A critical vulnerability affecting Squid proxy versions These security flaws impact multiple Squid proxy deployments in Squid proxy, tracked as CVE-2026-61642 with a CVSS score of 9.8, allows request smuggling attacks via improper enforcement of behavioral workflows, exploiting HTTP/1.1 Transfer-Encoding to bypass security mechanisms and store malicious payloads within the web cache. This flaw impacts multiple Squid proxy deployments, specifically versions 3.0 through 7.5, exposing internal corporate infrastructure to severe risks of cache poisoning and malicious content distribution if left unpatched. Additionally, two other vulnerabilities, SQUID-2026:8 and SQUID-2026:7, introduce stack-based buffer overflows due to improper input validation, allowing attackers to perform out-of-bounds writes during ICAP authentication or basic HTTP authentication with a peer server, affecting versions 3.0 through 7.7. These security flaws expose thousands of enterprise networks relying on Squid as a widely deployed caching proxy for web traffic to severe risks if left unpatched.
We recommend you to update Squid to version 7.6 or 7.7.[/subscribe_to_unlock_form]
A critical vulnerability affecting Squid proxy versions These security flaws impact multiple Squid proxy deployments in Squid proxy, tracked as CVE-2026-61642 with a CVSS score of 9.8, allows request smuggling attacks via improper enforcement of behavioral workflows, exploiting HTTP/1.1 Transfer-Encoding to bypass security mechanisms and store malicious payloads within the web cache. This flaw impacts multiple Squid proxy deployments, specifically versions 3.0 through 7.5, exposing internal corporate infrastructure to severe risks of cache poisoning and malicious content distribution if left unpatched. Additionally, two other vulnerabilities, SQUID-2026:8 and SQUID-2026:7, introduce stack-based buffer overflows due to improper input validation, allowing attackers to perform out-of-bounds writes during ICAP authentication or basic HTTP authentication with a peer server, affecting versions 3.0 through 7.7. These security flaws expose thousands of enterprise networks relying on Squid as a widely deployed caching proxy for web traffic to severe risks if left unpatched.
We recommend you to update Squid to version 7.6 or 7.7.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]