Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-62168

76
FAUCET Score

CVE-2025-62168 is a critical information disclosure vulnerability in Squid caching proxy versions prior to 7.2. It allows a remote attacker to bypass browser security and extract HTTP authentication credentials from error messages, even without Squid being configured for HTTP authentication. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and can lead to the disclosure of sensitive internal security tokens or credentials. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating high awareness. Organizations using affected Squid versions should upgrade to 7.2 or disable debug information via the "email_err_data off" configuration.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.2CPE matchmatch criteria
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
62.87%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-62168 · Apr 2, 2026
This CVE's current EPSS score of 0.6287 is in the 98th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 squid 6.13-3 on Azure Linux 3.0Fixed in: 6.13-3
microsoftpatch availablevia msrc
Product: 20164-17084Fixed in: 6.13-3
microsoftpatch availablevia msrc
Product: 20565-17084Fixed in: 6.13-3
microsoftpatch availablevia msrc
Product: azl3 squid 6.13-1 on Azure Linux 3.0Fixed in: 6.13-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: squid:4-8020020251028004321.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: squid:4-8040020251024000101.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: squid:4-8040020251024000101.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: squid:4-8060020251027230224.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: squid:4-8060020251027230224.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: squid:4-8060020251027230224.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: squid:4-8080020251029094904.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: squid:4-8080020251029094904.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: squid-7:5.5-22.el9_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: squid-7:5.2-1.el9_0.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: squid-7:5.5-5.el9_2.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: squid-7:5.5-13.el9_4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: squid-7:5.5-19.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: squid-7:6.10-6.el10_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: squid-7:6.10-5.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: squid-7:3.5.20-17.el7_9.15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: squid:4-8100020251023131551.489197e6
View patch

Vendor Advisories (2)

redhatCVE-2025-62168Important

squid-cache: Squid vulnerable to information disclosure via authentication credential leakage in error handling

Oct 17, 2025
microsoft2025-Oct/CVE-2025-62168Critical

Squid vulnerable to information disclosure via authentication credential leakage in error handling

Oct 14, 2025

References

openwall.com / lists/oss-security/2025/11/05/6
github.com / squid-cache/squid/commit/0951a0681011dfca3d78c84fd7f1e19c78a4443f
Patch
github.com / squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr
MitigationThird Party Advisory