[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNMtVuoYxVKKflx5x_bMcxkTUfYbcdJS8SrnNYvaixw0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"0a300bf7-2deb-4950-a572-52fa21383db3","29-year-old-squid-proxy-bug-exposes-cleartext-http-traffic-across-users","17bbd64d-9822-4ef1-8c8a-d0d541365cb7","29-Year-Old Squid Proxy Bug Exposes Cleartext HTTP Traffic Across Users","A decades-old flaw in the widely-used Squid proxy, rooted in a legacy FTP-parsing change, allows any authenticated user to read cleartext HTTP requests—including credentials and session tokens—belonging to other users on the same proxy. The vulnerability is present in Squid's default configuration, meaning organizations running out-of-the-box deployments are exposed without any additional misconfiguration required. This case highlights the danger of unpatched legacy code in critical network infrastructure, where a single bug can silently undermine the confidentiality of all proxied traffic. The existence of public proof-of-concept code significantly raises the urgency of remediation, even though no active exploitation has yet been confirmed.","**Immediate actions:**\n- Apply the latest Squid patch or upgrade to a non-vulnerable version as soon as it becomes available.\n- Audit all Squid proxy deployments to identify instances running default configurations and assess exposure.\n- Restrict proxy access to only explicitly authorized users and enforce strong authentication to reduce the blast radius of credential leakage.\n\n**Long-term improvements:**\n- Integrate Squid and other network proxy components into your vulnerability management program with regular, automated scanning.\n- Enforce HTTPS\u002FTLS end-to-end for all proxied traffic to reduce the value of any future plaintext leakage vulnerabilities.\n- Maintain a current, accurate software inventory (SBOM) of all network infrastructure components to enable rapid identification of affected systems during future disclosures.\n\n**Detection measures:**\n- Enable detailed access logging on proxy servers and alert on anomalous patterns such as users accessing unusual volumes of cross-user session data.\n- Deploy network monitoring to detect unexpected lateral data flows through the proxy layer.\n- Subscribe to security advisories for all critical infrastructure software (e.g., Squid mailing lists, NVD feeds) to ensure zero-day and long-latent vulnerabilities are actioned promptly.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SC-8: Transmission Confidentiality and Integrity","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST CSF ID.AM-2: Software platforms and applications are inventoried","GDPR Article 32: Security of Processing (confidentiality of personal data in transit)","ITIL: Change Enablement \u002F Emergency Change for Critical Patch Deployment","published","2026-06-22T16:21:13.962106+00:00","2026-06-22T16:21:13.645+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002F29-year-old-squid-proxy-bug-squidbleed.html","29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests-41444a","29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]