CVE-2024-23638Disclosure(squid-cache / squid)

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for squid-cache squid systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-825CWE-672

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squid

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
squid

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • CyDhaal@CyberDhaal
    Disclosure

    1/3 Squidbleed (CVE-2024-23638) A heap buffer over-read in Squid Proxy’s legacy Gopher gateway has been leaking sensitive memory contents since 1996. Unauthenticated attackers can extract auth tokens, TLS private keys, session data, and internal configs from millions of instances worldwide. This is infrastructure grade exposure that somehow survived three decades. Full technical breakdown + IOCs: https://cydhaal.com/squidbleed-memory-leak-in-squid-proxy-undetected-since-1990s/ #Squidbleed #InfoSec #CyberSecurity #SquidProxy #Vulnerability #CVE #NetworkSecurity

    Post summary

    Squid Proxy’s legacy Gopher gateway contains a long‑undetected heap buffer over‑read that allows unauthenticated attackers to exfiltrate sensitive data, with a technical breakdown now publicly disclosed.

    1000062
    510 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquid-cachesquid---

Explore more