Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

0
Medium
Vulnerability
Published: 06/22/2026 (06/22/2026, 13:22:31 UTC)
Source: SecurityWeek

Description

Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek .

Affected software

Affected versions
<7.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/22/2026, 13:24:18 UTC

Technical Analysis

Squidbleed is a Heartbleed-style memory leak vulnerability in the Squid Proxy FTP parser that allows reading beyond buffer boundaries into memory regions containing uncleared HTTP request data from previous users. Exploitation requires an attacker-controlled FTP server reachable by the proxy. The vulnerability primarily threatens shared proxy environments such as corporate networks, schools, and public Wi-Fi hotspots, where multiple users share the same Squid instance. Only cleartext HTTP traffic is exposed; HTTPS connections tunneled via CONNECT are not affected. The vulnerability was discovered with AI assistance and patched in Squid version 7.6 (June 2026) with the fix merged in version 8 (April 2026). Mitigation includes applying the patch or disabling FTP support if not needed.

Potential Impact

An attacker controlling an FTP server reachable from a vulnerable Squid proxy can exploit this flaw to read sensitive HTTP request data from other users routed through the same proxy. This may include authentication credentials, session tokens, and API keys transmitted in cleartext HTTP. The exposure is limited to unencrypted HTTP traffic and does not affect HTTPS traffic tunneled through the proxy. The vulnerability poses a medium risk primarily in shared proxy environments where multiple users' traffic is proxied together.

Mitigation Recommendations

A patch fixing this vulnerability is available and was shipped in Squid version 7.6 (June 2026), with the fix merged in version 8 (April 2026). Users should upgrade to at least version 7.6 to remediate the issue. If FTP support is not required, disabling FTP support in Squid provides an effective mitigation. No other specific mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/","fetched":true,"fetchedAt":"2026-06-22T13:24:11.468Z","wordCount":1059}

Threat ID: 6a39377beed863c81edd452f

Added to database: 06/22/2026, 13:24:11 UTC

Last enriched: 06/22/2026, 13:24:18 UTC

Last updated: 06/23/2026, 02:51:32 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses