Squid is a widely deployed open-source HTTP caching proxy and web-gateway product that handles request filtering and content acceleration for many enterprise networks and ISPs, despite its narrowly focused product line. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of internet-facing proxy infrastructure as a pivot point and the accessibility of attack surface in proxy parsing and request handling. Vulnerabilities concentrate in the core Squid proxy product and recur through weakness classes including improper input validation and related parsing defects that are characteristic of gateway software processing untrusted network traffic. Defenders should treat Squid advisories as requiring prompt attention on exposed gateway instances; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squid over time
Signals from CVEs in this vendor scope (152 CVEs).
152 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31806MEDIUM An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro | May 27, 2021 | 6.5 | 81 | NO | YES |
CVE-2025-62168HIGH Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulne | Oct 17, 2025 | 7.5 | 76 | NO | YES |
CVE-2024-25617HIGH Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Ser | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2023-46847HIGH Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configu | Nov 3, 2023 | 7.5 | 70 | NO | NO |
CVE-2023-49285HIGH Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messag | Dec 4, 2023 | 7.5 | 69 | NO | NO |
CVE-2016-4553HIGH client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-p | May 10, 2016 | 8.6 | 69 | NO | NO |
CVE-2016-4054HIGH Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. | Apr 25, 2016 | 8.1 | 68 | NO | NO |
CVE-2013-4123MEDIUM client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header. | Sep 16, 2013 | 5.0 | 66 | NO | YES |
CVE-2021-33620MEDIUM Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a heade | May 28, 2021 | 6.5 | 65 | NO | NO |
CVE-2020-8450HIGH An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. | Feb 4, 2020 | 7.3 | 64 | NO | NO |
Signals from CVEs in this vendor scope (152 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squid.
Media articles that mention a CVE ID that affects a product developed by Squid — matched by CVE ID, not by vendor name.