squid-cache has 3 CVEs on record between 2023 and 2026. 2 were published in the last 90 days. The median CVSS is 6.5 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- squid 3
Worst active — by depth score
CVE-2023-46847High· 8.6Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.65CVE-2026-47729Medium· 6.5Squid is a caching proxy for the Web48CVE-2026-50012Medium· 5.5Squid is a caching proxy for the Web31
squid-cache vulnerabilities
CVEs affecting squid-cache, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-50012Medium· 5.5Squid is a caching proxy for the Web
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest'…
CVE-2026-47729Medium· 6.5PoCSquid is a caching proxy for the Web
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…
CVE-2023-46847High· 8.6Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.