Square's vulnerability footprint concentrates in a modestly sized set of widely embedded developer libraries and payment-processing tools, including HTTP clients (OkHttp, Retrofit) and version-control utilities that sit deep in application dependency chains. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including improper certificate validation, command injection, and path traversal that are characteristic of libraries handling network communication, credential management, and file operations. Defenders should track this vendor's releases closely for downstream impact, as fixes to foundational libraries may require cascading updates across dependent applications; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squareup over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36645CRITICAL A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version v0.0.0 i | Jan 7, 2023 | 9.8 | 30 | NO | NO |
CVE-2018-1000844CRITICAL Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attack | Dec 20, 2018 | 9.1 | 27 | NO | NO |
CVE-2015-8969CRITICAL git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as argume | Nov 3, 2016 | 9.8 | 26 | NO | NO |
CVE-2018-1000850HIGH Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can r | Dec 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2015-8968HIGH git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, t | Nov 3, 2016 | 8.8 | 24 | NO | NO |
CVE-2023-3635HIGH GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZI | Jul 12, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-3782MEDIUM DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP respons | Jul 19, 2023 | 5.9 | 22 | NO | NO |
CVE-2016-2402MEDIUM OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned truste | Jan 30, 2017 | 5.9 | 22 | NO | NO |
CVE-2018-20200MEDIUM CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the | Apr 18, 2019 | 5.9 | 21 | NO | NO |
CVE-2023-0833MEDIUM A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an il | Sep 27, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squareup.
Media articles that mention a CVE ID that affects a product developed by Squareup — matched by CVE ID, not by vendor name.