Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-squid | Sep 20, 2017 | Jan 27, 2017 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-squidamazon-linux-ami-2-upgrade-squid-debuginfoamazon-linux-ami-2-upgrade-squid-migration-scriptamazon-linux-ami-2-upgrade-squid-sysvinit | Jun 6, 2023 | Jan 27, 2017 | |
| Amazon_linux | — | amazon-linux-upgrade-squid | Jun 9, 2023 | Dec 16, 2016 |
| Freebsd | freebsd-upgrade-package-squidfreebsd-upgrade-package-squid-devel | Dec 23, 2016 | Dec 23, 2016 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-squidhuawei-euleros-2_0_sp2-upgrade-squid-migration-script | Dec 4, 2019 | Jan 27, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-squidhuawei-euleros-2_0_sp3-upgrade-squid-migration-script | Dec 18, 2019 | Jan 27, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-squidhuawei-euleros-2_0_sp5-upgrade-squid-migration-script | Nov 19, 2019 | Jan 27, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-web-proxy-squid-3-5-23-0-175-3-17-0-1-0 | May 29, 2017 | Jan 27, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Dec 16, 2016 | |
| Suse | — | suse-upgrade-squid | Jan 14, 2017 | Dec 16, 2016 |
| Ubuntu | ubuntu-upgrade-squid3 | Feb 7, 2017 | Dec 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub