A critical heap buffer overread vulnerability, dubbed Squidbleed, has been discovered in the widely used Squid web proxy. This flaw, tracked as CVE-2026-47729, has existed in the software's FTP directory-listing parser since 1997. The vulnerability allows a trusted client to leak internal memory from the proxy, potentially exposing cleartext HTTP requests, passwords, and API keys. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
