Squidbleed: 29-Year-Old Squid Proxy Bug Leaks HTTP Credentia

🟠 High | Source: The Hacker News A 29-year-old heap over-read vulnerability in the Squid web proxy, dubbed ‘Squidbleed’, allows any user already permitted to send traffic through a shared proxy to read another user’s cleartext HTTP requests, including credentials and session tokens. The flaw originates from a 1997 FTP-parsing change and remains exploitable in Squid’s default configuration today. Exposure is broad given Squid’s widespread use as a forward proxy in enterprise and cloud environments. ...

22 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more