Squid
Vendor:
First CVE: Mar 8, 2002 · Active for 24 years
148
Total CVEs
More Total CVEs than 99% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Squid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2002
24 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
CVE Severity & Scoring
Squid148 CVEs
51%
41%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.4%)
Network84 (56.8%)
Unknown62 (41.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low76 (51.4%)
High10 (6.8%)
Unknown62 (41.9%)
User Interaction
None79 (53.4%)
Unknown62 (41.9%)
Required7 (4.7%)
Privileges Required
Low14 (9.5%)
High2 (1.4%)
None70 (47.3%)
Unknown62 (41.9%)
Top CVEs
Signals from CVEs in this product scope (148 CVEs).
148 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31806MEDIUM An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro | May 27, 2021 | 6.5 | 81 | NO | YES |
CVE-2025-62168HIGH Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulne | Oct 17, 2025 | 7.5 | 76 | NO | YES |
CVE-2024-25617HIGH Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Ser | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2023-46847HIGH Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configu | Nov 3, 2023 | 7.5 | 70 | NO | NO |
CVE-2023-49285HIGH Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messag | Dec 4, 2023 | 7.5 | 69 | NO | NO |
CVE-2016-4553HIGH client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-p | May 10, 2016 | 8.6 | 69 | NO | NO |
CVE-2016-4054HIGH Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. | Apr 25, 2016 | 8.1 | 68 | NO | NO |
CVE-2013-4123MEDIUM client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header. | Sep 16, 2013 | 5.0 | 66 | NO | YES |
CVE-2021-33620MEDIUM Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a heade | May 28, 2021 | 6.5 | 65 | NO | NO |
CVE-2020-8450HIGH An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. | Feb 4, 2020 | 7.3 | 64 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (148 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.4% of CVEs· 96th percentile
Nuclei
1 CVE
0.7% of CVEs· 96th percentile
ExploitDB
6 CVEs
4.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (148 CVEs).
Media Mentions
Signals from CVEs in this product scope (148 CVEs).
Top CNAs Publishing CVEs For Squid
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.9 | 4 | 7.8 | 40.9% | 0 | 0 |
| 4.0.8 | 8 | 7.5 | 35.9% | 0 | 0 |
| 4.0.7 | 10 | 7.5 | 33.7% | 0 | 0 |
| 4.0.6 | 14 | 7.5 | 28.3% | 0 | 0 |
| 4.0.5 | 15 | 7.4 | 28.1% | 0 | 0 |
| 4.0.4 | 15 | 7.4 | 28.1% | 0 | 0 |
| 4.0.3 | 14 | 7.5 | 28.3% | 0 | 0 |
| 4.0.2 | 14 | 7.5 | 28.3% | 0 | 0 |
| 4.0.16 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.15 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.14 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.13 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.12 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.11 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.10 | 1 | 7.5 | 6.8% | 0 | 0 |
| 4.0.1 | 14 | 7.5 | 28.3% | 0 | 0 |
| 3.5.9 | 8 | 7.3 | 30.3% | 0 | 0 |
| 3.5.8 | 8 | 7.3 | 30.3% | 0 | 0 |
| 3.5.7 | 8 | 7.3 | 30.3% | 0 | 0 |
| 3.5.6 | 8 | 7.3 | 30.3% | 0 | 0 |