A newly disclosed flaw in Squid Proxy can expose data from other users who share the same proxy server. Tracked as CVE-2026-47729 and dubbed 'Squidbleed,' the bug is a memory over-read in Squid’s FTP parser that has reportedly existed since 1997. An attacker must control an FTP server reachable through the proxy, and the leak can expose prior users’ cleartext HTTP request data, including credentials, session tokens, and API keys. A fix was merged for Squid 8 in April 2026 and released in Squid 7.6 in June 2026; disabling FTP support is a mitigation.
Why it matters: Organizations using Squid in shared environments such as companies, schools, and public hotspots may be exposing sensitive web traffic if they have not updated. Admins should upgrade to fixed versions or disable FTP support, especially where cleartext HTTP is still in use or Squid terminates Transport Layer Security (TLS).
Bruce Schneier
2026.07.10
96% relevant
This is a short secondary write-up of the same underlying event: the 'Squidbleed' information-disclosure flaw in Squid Proxy that can expose other users' web requests on shared proxies.
2026.06.23
97% relevant
This article is a direct report on the same Squidbleed event, adding detail on the bug’s 1997 origin, the FTP directory-listing parsing flaw, the conditions required for exploitation, and that the fix shipped in Squid v7.6 on June 8.
info@thehackernews.com (The Hacker News)
2026.06.22
97% relevant
This is another report on the same Squidbleed vulnerability, describing the longstanding Squid Proxy bug and its impact on shared proxy deployments that can expose other users' unencrypted HTTP requests.
Eduard Kovacs
2026.06.22
100% relevant
This article appears to be the initial broad disclosure of CVE-2026-47729, including the vulnerability details, affected software, attack requirements, and patch availability.
← Back to all stories