Squidbleed: memory leak in Squid proxy patched after 29 years
Calif has disclosed a vulnerability it calls Squidbleed, tracked as CVE-2026-47729. It is a heap buffer overread in Squid Proxy's FTP directory listing parser, and according to Calif it has been present since 1997. Squid leaks internal memory when parsing a malformed FTP listing with no filename after the timestamp. Because Squid enables FTP support by default and permits TCP port 21 in its default Safe_ports ACL, an attacker only needs to control an FTP server reachable through the proxy. Squid fixed the flaw in version 7.6, released on 8 June.
What this means for your organisation
Impact depends on how the proxy is used. In shared proxy environments, an attacker on the same Squid instance as the victims may recover stale data from recycled memory buffers, including cleartext HTTP requests and headers carrying authorisation tokens. HTTPS traffic relayed only through opaque CONNECT tunnels is less exposed, while cleartext HTTP and TLS-terminating deployments are at risk. For organisations with a shared outbound proxy, that means data from one department can leak to another party on the same instance.
Berigo recommends
- Upgrade Squid to version 7.6 or later on every proxy, including internal-only instances.
- Remove port 21 from Safe_ports and disable FTP support unless the business genuinely needs it.
- Identify which proxies terminate TLS and patch those first.
- Rotate API keys and tokens that have passed through a shared, unpatched proxy.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch