CVE-2026-50012Patch(squid-cache / squid)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch squid-cache squid systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squid

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-15); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Products
squid

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-06-15: 2Mentions · 2026-06-17: 2Mentions · 2026-06-18: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-06-15: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-23: 206-1506-1706-1806-2306-24
Signal classification3 categories
Patch
450.0%
Disclosure
337.5%
Active Exploitation
112.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-06-152
Disclosure1Patch1
2026-06-172
Disclosure1Patch1
2026-06-181
Disclosure1
2026-06-232
Patch2
2026-06-241
Active Exploitation1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    2 CVEs in Squid https://openwall.com/lists/oss-security/2026/06/12/1 CVE-2026-47729: Out-of-Bounds Read from random unrelated transactions when accessing a misbehaving FTP server CVE-2026-50012: Heap-based Buffer Overflow when sending maliciously crafted replies to cache_digest request messages, fixed in 7.6

    Post summary

    The post announces two newly disclosed Squid vulnerabilities, describing an OOB read and a heap buffer overflow; it notes that CVE‑2026‑50012 is fixed in version 7.6 but provides no PoC, exploit, or evidence of active exploitation.

    12050585
    4.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    脆弱性についての正式発表はまだだが、6/7にリリースされたSquidのv7.6で修正された脆弱性2件の情報が解禁。 oss-sec: Squid CVE-2026-47729 and CVE-2026-50012 https://seclists.org/oss-sec/2026/q2/896

    Post summary

    Information about two CVEs (CVE-2026-47729, CVE-2026-50012) that were fixed in Squid v7.6 is now publicly available, though a formal vendor announcement has not yet been made.

    100321.0K
    7.0K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    先程公式からもアドバイザリが出たようです。 CVE-2026-47729 SQUID-2026:4 Memory disclosure in FTP gateway https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg CVE-2026-50012 SQUID-2026:5 Memory corruption in cache_digest reply handling https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284

    Post summary

    An official advisory was released for two new Squid CVEs (CVE-2026-47729 and CVE-2026-50012) detailing memory disclosure and memory corruption vulnerabilities; the text does not include exploit details or patch specifics.

    00010343
    6.9K followersView on X
  • Cyberdark Imapct@kenebeii
    Disclosure

    🔐 セキュリティトレンド (18:04 JST) ① プロキシサーバーSquid がFTPゲートウェイの境界外読み取り(CVE-2026-47729)と ... https://rocket-boys.co.jp/security-measures-lab/squid-cve-2026-47729-cve-2026-50012/ ② ソフトバンクG サイバー攻撃対策サービスを提供へ最新の経済ニュース【随時更新】 - ABEMA https://abema.tv/video/episode/89-44_s0_p512745 ③ 前立腺がん治療薬「アーリーダ」 P3試験で手術前後投与により転移・死亡リスクが有意に低下 J&J https://iyakutsushinsha.com/2026/06/17/%E5%89%8D%E7%AB%8B%E8%85%BA%E3%81%8C%E3%82%93%E6%B2%BB%E7%99%82%E8%96%AC%E3%80%8C%E3%82%A2%E3%83%BC%E3%83%AA%E3%83%BC%E3%83%80%E3%80%8D%E3%80%80p3%E8%A9%A6%E9%A8%93%E3%81%A7%E6%89%8B%E8%A1%93%E5%89%8D/ ④ 「SNS投稿から情報漏えい」約50社に1社が経験 東京商工リサーチ調査 - Yahoo!ニュース https://news.yahoo.co.jp/articles/5f36fbbb0fccd2b8bca59003d423dec76a21d922 ⑤ 米・任天堂ハッキング被害で約3億円の身代金を要求されたか。ハッカーによる従業員情報漏洩の噂 ... https://topics.smt.docomo.ne.jp/amp/article/gamespark/trend/gamespark-168080 #セキュリティ #CyberSecurity

    Post summary

    The tweet announces the discovery of an out‑of‑bound read vulnerability in Squid's FTP gateway (CVE‑2026‑47729) and links to a security lab post, but it does not provide any proof‑of‑concept, exploit, patch, or evidence of active exploitation.

    00010182
    544 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting squid-cache Squid (CVE-2026-50012) https://vuldb.com/vuln/370670/cti

    Post summary

    CTI analysts report numerous observed activities exploiting Squid via CVE‑2026‑50012, indicating active malicious use but lacking details on the exploit or patch.

    0000094
    2.2K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Patch

    🚨 UPDATE — Squidbleed CVE-2026-47729: Critical remediation detail — Squid 7.6 does NOT fix Squidbleed. Squid maintainer Amos Jeffries corrected public statements saying 7.6 patches the flaw. It doesn’t. The real fix ships in Squid 7.7, which has NOT been released yet. What 7.6 fixed: CVE-2026-50012 (cache_digest heap overflow) only. If you patched to 7.6 assuming Squidbleed was closed, you are still vulnerable. Interim mitigation: remove port 21 from Safe_ports in squid.conf and restart. Disable FTP support entirely unless you have a specific, current business reason to allow FTP proxying. This removes the attack surface with zero functionality impact in most organizations. Full breakdown 👇 https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html

    Post summary

    The post clarifies that Squid 7.6 does not contain the Squidbleed fix; users should use the interim mitigation of disabling FTP support, and the official patch will arrive with unreleased Squid 7.7.

    0000066
    84 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    プロキシサーバーSquid がFTPゲートウェイの境界外読み取り(CVE-2026-47729)とcache_digestのヒープバッファオーバーフロー(CVE-2026-50012)の脆弱性を修正 https://rocket-boys.co.jp/security-measures-lab/squid-cve-2026-47729-cve-2026-50012/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Squid has issued patches for CVE‑2026‑47729 (out‑of‑bounds read) and CVE‑2026‑50012 (heap buffer overflow), as announced on the security lab website.

    00000100
    431 followersView on X
  • Can Artuc@canartuc
    Patch

    Squid 7.6 patches two memory bugs: CVE-2026-47729, an out-of-bounds read in the FTP gateway triggered by a misbehaving upstream FTP server, and CVE-2026-50012, a heap overflow in cache digests on --enable-cache-digests builds. If your proxy still gateways FTP, why is it still on?

    Post summary

    Squid 7.6 patches two memory bugs—CVE‑2026‑47729 (out‑of‑bounds read in the FTP gateway) and CVE‑2026‑50012 (heap overflow in cache digests on --enable-cache-digests builds). No exploitation activity or PoC is mentioned.

    0000035
    172 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquid-cachesquid---

Explore more