Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Jul 22, 2026 | Jul 16, 2026 |
| Amazon Linux Ami 2 | — | Upgrade squidUpgrade squid-debuginfoUpgrade squid-migration-scriptUpgrade squid-sysvinit | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade squidUpgrade squid-debuginfoUpgrade squid-debugsource | Jul 17, 2026 | Jul 16, 2026 |
| Debian | — | Upgrade squid | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 23, 2026 |
| Ubuntu | — | Upgrade squid | Jun 17, 2026 | Jun 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub