CVE-2026-47729Disclosure(squid-cache / squid)

CRITICALCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 21 mentions and remains active

Immediate actions

  • Patch squid-cache squid systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-1289

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squid

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 101 mentions across 22 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 27 signals
  • Technical details provided in 68 signals
  • Disclosure: 54 classified signals
  • General: 21 classified signals
  • Peaked 14d ago at 21 mentions (2026-06-23); latest day: 2
  • 101 total mentions across 22 days

Affected systems

Products
squid

Deep dive

Activity timeline101 mentions / 22d
05111621Mentions · 2026-06-15: 2Mentions · 2026-06-17: 2Mentions · 2026-06-18: 2Mentions · 2026-06-19: 8Mentions · 2026-06-20: 1Mentions · 2026-06-21: 2Mentions · 2026-06-22: 19Mentions · 2026-06-23: 21Mentions · 2026-06-24: 15Mentions · 2026-06-25: 2Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Mentions · 2026-07-01: 2Mentions · 2026-07-02: 6Mentions · 2026-07-06: 1Mentions · 2026-07-07: 4Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-15: 1Mentions · 2026-07-16: 5Mentions · 2026-07-20: 2PoC Mentioned / Linked · 2026-06-20: 1PoC Mentioned / Linked · 2026-06-22: 6PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-24: 5PoC Mentioned / Linked · 2026-07-16: 3Exploit Tool / Code · 2026-06-22: 1Exploit Tool / Code · 2026-06-24: 1Exploit Tool / Code · 2026-07-02: 1Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-22: 2Active Exploitation · 2026-07-11: 1Patch / Workaround · 2026-06-15: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-22: 6Patch / Workaround · 2026-06-23: 7Patch / Workaround · 2026-06-24: 5Patch / Workaround · 2026-07-02: 2Patch / Workaround · 2026-07-07: 3Technical Details · 2026-06-15: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 4Technical Details · 2026-06-20: 1Technical Details · 2026-06-21: 2Technical Details · 2026-06-22: 14Technical Details · 2026-06-23: 15Technical Details · 2026-06-24: 11Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-27: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 5Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 3Technical Details · 2026-07-08: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-15: 106-1506-1806-2006-2206-2406-2607-0107-0607-0807-1107-1607-20
Signal classification5 categories
Disclosure
5453.5%
General
2120.8%
Patch
1413.9%
PoC
98.9%
Active Exploitation
33.0%
Referenced assets59 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-152
Disclosure1Patch1
2026-06-172
Disclosure1Patch1
2026-06-182
Disclosure1General1
2026-06-198
Active Exploitation1Disclosure6General1
2026-06-201
PoC1
2026-06-212
Disclosure2
2026-06-2219
Active Exploitation1Disclosure11General3Patch2PoC2
2026-06-2321
Disclosure12General6Patch3
2026-06-2415
Disclosure6General3Patch3PoC3
2026-06-252
Disclosure1General1
2026-06-262
Disclosure1General1
2026-06-271
Disclosure1
2026-07-012
Disclosure1General1
2026-07-026
Disclosure4Patch2
2026-07-061
Disclosure1
2026-07-074
Disclosure2Patch2
2026-07-081
Disclosure1
2026-07-101
Disclosure1
2026-07-111
Active Exploitation1
2026-07-151
General1
2026-07-165
General2PoC3
2026-07-202
Disclosure1General1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ Squidbleed: A 29-Year-Old Heap Over-Read Leaks Cleartext HTTP in Squid (CVE-2026-47729) https://darkwebinformer.com/squidbleed-a-29-year-old-heap-over-read-leaks-cleartext-http-in-squid-cve-2026-47729/ https://t.co/KnEZJUrbzy

    Post summary

    The tweet announces a newly disclosed heap over-read vulnerability (CVE‑2026‑47729) in Squid that leaks cleartext HTTP traffic.

    02501454723.2K
    226.8K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    🤯 A 1997 parser bug is still haunting Squid. Squidbleed (CVE-2026-47729) can leak another user’s cleartext HTTP request through a shared Squid proxy, including credentials or session tokens. See how the bug works 🠖 https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html #vulnerability

    Post summary

    CVE‑2026‑47729 is a newly disclosed 1997 parser bug in Squid that can leak cleartext HTTP requests, including credentials, through a shared proxy. No active exploitation, patch, or PoC code is mentioned.

    0230701816.3K
    2.2M followersView on X
  • Stanislav Fort@stanislavfort
    General

    That "Squidbleed" vulnerability (CVE-2026-47729) that Mythos "discovered" in April? Yeah no @AISLE_Inc actually already reported it back in March, full 44 days before Mythos. Another great live example of the value of the system over the model in zero-day discovery. https://t.co/rYbUVcMXmi

    Post summary

    The tweet merely comments on the discovery timeline for Squidbleed (CVE‑2026‑47729), claiming AISLE_Inc reported it first in March before Mythos.

    11227148.6K
    17.0K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    PoC

    Claude found a 29-year-old bug hiding in Squid Proxy. Sent Claude Mythos preview deep into the code. It came back with Squidbleed (CVE-2026-47729) 😗 Root cause: A tiny misunderstanding of how `strchr()` behaves with null terminators in C (per the C11 standard). Then it spotted a subtle Heap buffer overread that can leak data from other users’ sessions. overread in Squid’s FTP dir listing parser, that can leak with HTTP request data (including auth headers) from reused memory buffers. a Heartbleed-style memory leak affects every version in the default configuration. It was there since 1997, Audits missed it, AI didn’t. just did what decades of human audits couldn’t. It was in the code since a 1997 NetWare-related commit. Default config then vulnerable. Poc - http://blog.calif.io/p/squidbleed-cve-2026-47729

    Post summary

    A 29‑year‑old heap buffer overread in Squid Proxy (CVE‑2026‑47729) is disclosed, with a PoC link and detailed technical description, but no evidence of active exploitation, patches, or customization tools.

    115252204.8K
    51.9K followersView on X
  • Squidbleed@Squidbleed
    General

    The Squidbleed website is now live. A dedicated hub for CVE-2026-47729, technical breakdowns, vulnerability research, and future updates. Explore the story behind the 29-year-old bug. https://www.squidbleed.xyz A Calif Research Project. 🦑

    Post summary

    The post announces a new website dedicated to CVE‑2026‑47729, offering technical breakdowns and future updates, but provides no concrete details on proof of concept, exploitation, or remediation.

    1371441116.7K
    68 followersView on X
  • Squidbleed@Squidbleed
    General

    Squidbleed now has its own home. Follow Squidbleed for updates, research, technical analysis, and everything related to CVE-2026-47729. Squidbleed is a research project created by @calif_io. More discoveries ahead. 🦑

    Post summary

    The message announces the Squidbleed research project focused on CVE-2026-47729 but provides no technical details, PoC, or exploit information.

    26213703.8K
    68 followersView on X
  • 辻 伸弘 (nobuhiro tsuji)@ntsuji
    Disclosure

    Squid Proxyに29年間潜伏していた情報漏えい脆弱性「Squidbleed(CVE-2026-47729)」が発覚。 細工したFTP応答によりメモリ上の認証ヘッダやセッショントークン、APIキーなどが漏えいする可能性があるとのこと。 CVSS 6.5ですが認証情報窃取につながる点に注意ですね。 https://gbhackers.com/29-year-old-squid-proxy-vulnerability/

    Post summary

    The post announces the discovery of Squid Proxy’s 29‑year‑old vulnerability, Squidbleed (CVE‑2026‑47729), noting that crafted FTP responses may leak authentication headers, session tokens, and API keys; CVSS score is 6.5.

    11413879.2K
    28.7K followersView on X
  • ^mad@a_javadinezhad
    Disclosure

    یه داستان عجیب، پشم ریزون: یه باگ امنیتی به اسم Squidbleed (CVE-2026-47729) کشف شد تو پروکسی سرور Squidا که هزاران شرکت، مدرسه، و ISP ازش استفاده می‌کنن. نکته عجیب ریشه این باگ به یه commit از ژانویه ۱۹۹۷ برمی‌گرده! یعنی نزدیک به ۲۹ سال، با وجود صدها بار review و audit، هیچ انسانی پیداش نکرده بود. بالاخره مدل Claude Mythos طی یه بررسی روی کد قدیمی FTP این پروژه، این باگ رو پیدا کرد. https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/ https://blog.calif.io/p/squidbleed-cve-2026-47729

    Post summary

    A new SquidProxy vulnerability (CVE‑2026‑47729) was discovered after a 29‑year‑old commit; the post reports the discovery but offers no evidence of exploitation or remediation.

    11044103.7K
    2.8K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    El fallo Squidbleed, un error de 29 años en el proxy Squid, puede filtrar peticiones HTTP en texto plano Se ha descubierto una vulnerabilidad en el proxy Squid llamada Squidbleed (CVE-2026-47729) que permite filtrar datos confidenciales https://blog.elhacker.net/2026/06/el-fallo-squidbleed-un-error-de-29-anos.html

    Post summary

    A new vulnerability, Squidbleed (CVE-2026-47729), has been disclosed in the Squid proxy that can leak plaintext HTTP traffic, potentially exposing confidential data.

    01302853.8K
    141.3K followersView on X
  • yousukezan@yousukezan
    Disclosure

    1997年から存在していたとされるSquid Proxyの脆弱性「Squidbleed(CVE-2026-47729)」が公開された。FTPディレクトリ一覧の解析処理に起因する問題で、共有プロキシ環境において他ユーザーのHTTP認証ヘッダーやAPIキーなどの機密情報が漏えいする可能性がある。 影響を受けるのはFTPサポートが有効な標準構成のSquidだ。原因はFTPディレクトリ一覧パーサーのメモリ処理にあり、ファイル名を含まない不正なFTP応答を処理した際、C言語のstrchr関数によるNULL終端文字の扱いを考慮していなかったため、ポインタがバッファ境界を越えて進み、隣接するヒープメモリを読み取ってしまう。 Squidは4KB単位の固定サイズメモリプールを再利用する際に内容を消去しない。このため、以前処理されたHTTPリクエストのデータがメモリ上に残存する場合があり、攻撃者が制御するFTPサーバーから細工したディレクトリ一覧を送信することで、その残存データを取得できる可能性がある。実証ではAuthorizationヘッダーやAPIキーの漏えいが確認された。 HTTPS通信の大半はCONNECT方式でトンネル化されるため影響は限定的だが、SSLインスペクションを実施する企業環境や平文HTTPを利用する環境ではリスクが高まる。共有プロキシや公共ネットワークでの利用も影響を受けやすい。 修正パッチではNULL終端文字を確認する処理が追加された。研究者らは速やかな更新に加え、不要な場合はFTPサポートを無効化するよう推奨している。 https://gbhackers.com/29-year-old-squid-proxy-vulnerability/

    Post summary

    The article announces Squid Proxy’s long‑standing vulnerability CVE‑2026‑47729, demonstrates that FTP directory listing parsing can leak sensitive headers, and reports a patch that checks the NULL terminator while recommending disabling FTP support.

    01002493.4K
    14.8K followersView on X
  • Squidbleed@Squidbleed
    Disclosure

    Squidbleed is getting its own web hub. We’re building a dedicated place for the story, the research, the technical details, and what comes next. CVE-2026-47729 deserves more than a single post. Website coming soon. https://github.com/califio/publications/tree/main/MADBugs/squidbleed

    Post summary

    The post announces the creation of a dedicated hub for the Squidbleed vulnerability CVE-2026-47729, indicating upcoming detailed content, but no PoC, exploit, or technical details are supplied in this text.

    1200200305
    68 followersView on X
  • Horizon3.ai@Horizon3ai
    General

    Not every critical vuln leads to RCE. Sometimes it leaks the credentials that lead to one. Rapid Response test now available for Squidbleed (CVE-2026-47729). https://t.co/5BjTRWzvHR

    Post summary

    The tweet announces that a Rapid Response test for CVE‑2026‑47729 (Squidbleed) is now available, but provides no further details on exploits, patches, or technical specifics.

    1811262.1K
    2.9K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    Squidbleed (CVE-2026-47729) : un bug d'une ligne planqué depuis 1997 dans le proxy Squid. Repéré par une IA 👇 https://www.it-connect.fr/squidbleed-faille-proxy-squid-cve-2026-47729/ #cybersecurite https://t.co/aSG7ktWSHr

    Post summary

    The post announces a newly discovered Squid proxy vulnerability (CVE‑2026‑47729) flagged by AI, linking to a news article that provides basic details.

    0601181.2K
    11.6K followersView on X
  • danikkk_wqs@danikkk_wqs
    General

    AI found a bug that's 29 years old. Claude Mythos Preview analyzed more than 1,000 open-source projects. Found over 10,000 high and critical severity vulnerabilities. None of that is the story. Squidbleed. CVE-2026-47729. January 1997. Every security team on the planet looked at this code for three decades. Nobody caught it. Researchers pointed Mythos at the right file. It flagged the bug in minutes. Thirty years of human review. One afternoon of AI. The same model the US government restricted in an authorized red team exercise found vulnerabilities in NSA and Cyber Command in hours. It didn't hack them. It found the holes. Not the same thing. No security team can afford to read a thousand codebases. Mythos did it anyway. How many bugs like this are still waiting in the code you use every day?

    Post summary

    The text reports that an AI tool named Mythos identified an old vulnerability—CVE-2026-47729—in Squidbleed after 29 years, but it offers no technical details, exploit code, or remediation information.

    110127154
    355 followersView on X
  • L’algorisme@lalgorisme
    General

    🧵Un bug introduït al codi de Squid el 1997 s'ha descobert el 2026, i, un cop més, l'ha caçat una IA. Permet que un usuari d'una xarxa compartida llegeixi la petició HTTP d'un altre, credencials i tokens de sessió inclosos. Es diu Squidbleed (CVE-2026-47729).

    Post summary

    CVE‑2026‑47729, dubbed Squidbleed, is a newly discovered information‑disclosure flaw in Squid that lets a user on a shared network read another user’s HTTP requests and embedded credentials.

    1701121.1K
    5.9K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    PoC

    Squidbleed (CVE-2026-47729): Squid Proxy Memory Leak Details and PoC Disclosed https://securityonline.info/squidbleed-vulnerability/ https://t.co/yf4wik7iJ1

    Post summary

    Squidbleed (CVE‑2026‑47729) is a memory‑leak vulnerability in Squid Proxy with a self‑contained PoC disclosed. No exploit tool, patch, or active exploitation evidence is reported.

    0301021.2K
    12.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    Squidbleed CVE-2026-47729 için POC Exploit yayınlandı: https://github.com/0xBlackash/CVE-2026-47729

    Post summary

    A proof‑of‑concept exploit for the Squidbleed vulnerability (CVE‑2026‑47729) has been released on GitHub.

    110751.9K
    1.7K followersView on X
  • Squidbleed@Squidbleed
    General

    Forum Update Released 🦑 The Squidbleed Community Forum is now live. 🔹 Create your own threads 🔹 Discuss vulnerabilities and mitigations 🔹 Share research and PoCs 🔹 Exchange ideas with the community 🔹 Track the latest discussions around CVE-2026-47729 Join the discussion: https://squidbleed.xyz/forum This is the first release. More features, moderation tools, profiles, and community improvements are already in development.

    Post summary

    The forum announcement focuses on launching a community platform for discussing vulnerabilities and sharing PoCs, specifically referencing CVE-2026-47729, but offers no technical depth, exploitation evidence, or patch information.

    23171941
    68 followersView on X
  • Squidbleed@Squidbleed
    General

    The original Squidbleed research belongs to the incredible team at @calif_io. We’re simply a community project inspired by their work and the story behind CVE-2026-47729. We’ve reached out and hope to connect soon. 🦑

    Post summary

    The tweet only notes that the community project was inspired by the Squidbleed research and the story behind CVE‑2026‑47729, without providing any technical, exploit, or mitigation details.

    410901.8K
    68 followersView on X
  • Cristian Borghello@SeguInfo
    Disclosure

    Squidbleed (CVE-2026-47729): expone credenciales HTTP en texto plano de usuarios http://blog.segu-info.com.ar/2026/06/squidbleed-cve-2026-47729-expone.html

    Post summary

    Squidbleed (CVE-2026-47729) is disclosed as a vulnerability that exposes users' HTTP credentials in clear text.

    000861.9K
    38.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquid-cachesquid---

Explore more