Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-12527

55
FAUCET Score

CVE-2019-12527 is a heap-based buffer overflow vulnerability affecting Squid versions 4.0.23 through 4.7, as well as various distributions like Debian and Red Hat. The flaw stems from Squid's Basic Authentication process, where a global buffer is used to store decoded data without proper length checks, allowing user-controlled input to exceed buffer boundaries. Rated 8.8 HIGH (CVSSv3.1), this vulnerability has a low attack complexity and could lead to high impact on confidentiality, integrity, and availability if exploited. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.23, <= 4.7CPE matchmatch criteria
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
49.04%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.4904 is in the 99th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: squid:4-8000020190823131713.f8e95b4e
View patch

Vendor Advisories (1)

redhatCVE-2019-12527Important

squid: heap-based buffer overflow in HttpHeader::getAuth

Jul 12, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-11/msg00053.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2019-11/msg00056.html
Broken Link
access.redhat.com / errata/RHSA-2019:2593
Third Party Advisory
github.com / squid-cache/squid/commits/v4
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ
seclists.org / bugtraq/2019/Aug/42
Mailing ListThird Party Advisory
usn.ubuntu.com / 4065-1
Third Party Advisory
debian.org / security/2019/dsa-4507
Third Party Advisory
securityfocus.com / bid/109143
Broken LinkThird Party AdvisoryVDB Entry
squid-cache.org / Versions/v4/changesets
Vendor Advisory
squid-cache.org / Versions/v4/changesets/squid-4-7f73e9c5d17664b882ed32590e6af310c247f320.patch
PatchVendor Advisory