
1/3 Squidbleed (CVE-2024-23638) A heap buffer over-read in Squid Proxy’s legacy Gopher gateway has been leaking sensitive memory contents since 1996. Unauthenticated attackers can extract auth tokens, TLS private keys, session data, and internal configs from millions of instances worldwide. This is infrastructure grade exposure that somehow survived three decades. Full technical breakdown + IOCs: https://cydhaal.com/squidbleed-memory-leak-in-squid-proxy-undetected-since-1990s/ #Squidbleed #InfoSec #CyberSecurity #SquidProxy #Vulnerability #CVE #NetworkSecurity
Post summary
Squid Proxy’s legacy Gopher gateway contains a long‑undetected heap buffer over‑read that allows unauthenticated attackers to exfiltrate sensitive data, with a technical breakdown now publicly disclosed.
