Squid

Vendor:

First CVE: Mar 8, 2002 · Active for 24 years

148
Total CVEs
More Total CVEs than 99% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Squid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2002
24 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

CVE Severity & Scoring

Squid148 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (1.4%)
Network84 (56.8%)
Unknown62 (41.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low76 (51.4%)
High10 (6.8%)
Unknown62 (41.9%)
User Interaction
None79 (53.4%)
Unknown62 (41.9%)
Required7 (4.7%)
Privileges Required
Low14 (9.5%)
High2 (1.4%)
None70 (47.3%)
Unknown62 (41.9%)

Top CVEs

Signals from CVEs in this product scope (148 CVEs).

148 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro
May 27, 20216.581NOYES
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulne
Oct 17, 20257.576NOYES
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Ser
Feb 14, 20247.572NONO
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configu
Nov 3, 20237.570NONO
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messag
Dec 4, 20237.569NONO
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-p
May 10, 20168.669NONO
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
Apr 25, 20168.168NONO
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.
Sep 16, 20135.066NOYES
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a heade
May 28, 20216.565NONO
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Feb 4, 20207.364NONO

Exploit Exposure

Signals from CVEs in this product scope (148 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.4% of CVEs· 96th percentile
Nuclei
1 CVE
0.7% of CVEs· 96th percentile
ExploitDB
6 CVEs
4.1% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (148 CVEs).

Media Mentions

Signals from CVEs in this product scope (148 CVEs).

Top CNAs Publishing CVEs For Squid

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.947.840.9%00
4.0.887.535.9%00
4.0.7107.533.7%00
4.0.6147.528.3%00
4.0.5157.428.1%00
4.0.4157.428.1%00
4.0.3147.528.3%00
4.0.2147.528.3%00
4.0.1617.56.8%00
4.0.1517.56.8%00
4.0.1417.56.8%00
4.0.1317.56.8%00
4.0.1217.56.8%00
4.0.1117.56.8%00
4.0.1017.56.8%00
4.0.1147.528.3%00
3.5.987.330.3%00
3.5.887.330.3%00
3.5.787.330.3%00
3.5.687.330.3%00