<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Web-Proxy on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/web-proxy/</link><description>Recent content in Web-Proxy on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 22 Jun 2025 14:29:46 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/web-proxy/index.xml" rel="self" type="application/rss+xml"/><item><title>Squidbleed: 29-Year-Old Squid Proxy Bug Leaks HTTP Credentia</title><link>https://zxcloudsecurity.co.uk/posts/squidbleed-squid-proxy-heap-over-read-cleartext-http-credential-leak/</link><pubDate>Mon, 22 Jun 2026 14:29:46 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/squidbleed-squid-proxy-heap-over-read-cleartext-http-credential-leak/</guid><description>The Squidbleed vulnerability in Squid Proxy exposes cleartext HTTP requests, credentials, and session tokens to other proxy users. Learn the security impac</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html">The Hacker News</a></p>
<hr>
<p>A 29-year-old heap over-read vulnerability in the Squid web proxy, dubbed &lsquo;Squidbleed&rsquo;, allows any user already permitted to send traffic through a shared proxy to read another user&rsquo;s cleartext HTTP requests, including credentials and session tokens. The flaw originates from a 1997 FTP-parsing change and remains exploitable in Squid&rsquo;s default configuration today. Exposure is broad given Squid&rsquo;s widespread use as a forward proxy in enterprise and cloud environments.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit all environments running Squid as a shared forward proxy — particularly where multiple tenants or workloads share the same proxy instance — and apply vendor patches or mitigations immediately; if no patch is yet available, consider restricting Squid to single-tenant deployments or replacing it with an alternative until a fix is confirmed.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html">29-Year-Old Squid Proxy Bug &lsquo;Squidbleed&rsquo; Can Leak Cleartext HTTP Requests</a></p>
]]></content:encoded></item></channel></rss>