CVE-2025-62168 is a critical information disclosure vulnerability in Squid caching proxy versions prior to 7.2. It allows a remote attacker to bypass browser security and extract HTTP authentication credentials from error messages, even without Squid being configured for HTTP authentication. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and can lead to the disclosure of sensitive internal security tokens or credentials. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating high awareness. Organizations using affected Squid versions should upgrade to 7.2 or disable debug information via the "email_err_data off" configuration.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
squid-cache: Squid vulnerable to information disclosure via authentication credential leakage in error handling
Oct 17, 2025Squid vulnerable to information disclosure via authentication credential leakage in error handling
Oct 14, 2025