CVE-2021-31806 is a Denial of Service vulnerability affecting Squid versions before 4.15 and 5.x before 5.0.6, as well as products from Debian, Fedora Project, and NetApp that utilize Squid. This flaw stems from a memory-management bug triggered by HTTP Range request processing, which can disrupt proxy services for all clients. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low privileges and no user interaction, leading to high availability impact. While not observed in active exploitation, a Metasploit module exists, and its high EPSS and FAUCET Risk scores indicate a significant potential for future exploitation, despite a lack of public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.15CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.0.6CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.