Feeds.4Sysops Critical Squid Proxy Vulnerability 'Squidbleed' Exposes User Data
Article Content
- •Squidbleed (CVE-2026-47729) is a critical memory leak vulnerability in Squid Proxy.
- •The flaw has existed since 1997 and can expose sensitive user data in shared environments.
- •A patch was released in June 2026, and disabling FTP support can help mitigate risks.
A memory leak vulnerability named Squidbleed, tracked as CVE-2026-47729, has been discovered in the Squid web proxy software, affecting versions since 1997. This flaw allows attackers to read beyond memory buffer boundaries in the FTP parser, potentially exposing sensitive data such as authentication credentials and API keys. The vulnerability is particularly dangerous in shared proxy environments, like corporate networks and public Wi-Fi, where multiple users access a single Squid instance. Exploitation requires control over an FTP server accessible from the proxy. A patch was merged into Squid version 8 in April 2026 and released in version 7.6 in June 2026. Disabling FTP support can mitigate risks if FTP is not needed. Researchers from Calif.io discovered the vulnerability with the help of Anthropic's Claude Mythos AI model.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track CVE-2026-47729 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Widespread Privacy Risks in Mobile VPN Apps Identified A recent analysis of over 800 free mobile VPN apps revealed significant security flaws, with many apps leaking personal data and requesting excessive permissions. Zimperium zLabs found that these vulnerabilities pose risks not only to individual users but also to organizations with BYOD policies, as these apps can…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…