{"id":"CVE-2026-47729","title":"Squid is a caching proxy for the Web","summary":"Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-125","CWE-1289"],"vendor":"squid-cache","product":"squid","affected":["squid < 7.6"],"patched":["squid 7.6"],"published":"2026-07-16","updated":"2026-07-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47729","references":[{"url":"https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8","label":"security-advisories@github.com"},{"url":"https://github.com/squid-cache/squid/pull/2408","label":"security-advisories@github.com"},{"url":"https://github.com/squid-cache/squid/pull/2409","label":"security-advisories@github.com"},{"url":"https://github.com/squid-cache/squid/releases/tag/SQUID_7_6","label":"security-advisories@github.com"},{"url":"https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.01503,"epssPercentile":0.72775,"ingestedAt":"2026-07-20T02:36:03.241Z","exploits":{"github":1,"githubRepos":["https://github.com/0xBlackash/CVE-2026-47729"],"checkedAt":"2026-09-21T15:29:12.546Z"},"exploitAvailable":true,"slug":"CVE-2026-47729","body":"## Overview\n\nSquid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.\n\n## Affected\n\n- `squid < 7.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `squid 7.6`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":5264,"id":"CVE-2026-47729","ts":1788887257839,"field":"exploit_available","old":"false","new":"true"},{"seq":4147,"id":"CVE-2026-47729","ts":1788886374281,"field":"exploit_available","old":"true","new":"false"},{"seq":2916,"id":"CVE-2026-47729","ts":1788883040107,"field":"exploit_available","old":"false","new":"true"},{"seq":1945,"id":"CVE-2026-47729","ts":1788882443186,"field":"exploit_available","old":"true","new":"false"},{"seq":1033,"id":"CVE-2026-47729","ts":1788881878132,"field":"exploit_available","old":"false","new":"true"}]}