Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Sep 20, 2017 | Jan 27, 2017 |
| Amazon Linux Ami 2 | — | Upgrade squid-debuginfoUpgrade squid-migration-scriptUpgrade squidUpgrade squid-sysvinit | Jun 6, 2023 | Jan 27, 2017 |
| Amazon_linux | — | Upgrade squid | Jun 9, 2023 | Dec 16, 2016 |
| Freebsd | — | Upgrade squidUpgrade squid-devel | Dec 23, 2016 | Dec 23, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squidUpgrade squid-migration-script | Dec 4, 2019 | Jan 27, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade squidUpgrade squid-migration-script | Dec 18, 2019 | Jan 27, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade squidUpgrade squid-migration-script | Nov 19, 2019 | Jan 27, 2017 |
| Oracle Solaris | — | Upgrade web/proxy/squid to version 3.5.23-0.175.3.17.0.1.0 on Solaris 11.3 | May 29, 2017 | Jan 27, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 16, 2016 |
| Suse | — | Upgrade squid | Jan 14, 2017 | Dec 16, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 7, 2017 | Dec 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub