CVE-2026-47729

EUVD-2026-44962
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72.5%
Affected Products (NVD)
VendorProductVersion
squid-cachesquid
𝑥
< 7.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
squid
bookworm
vulnerable
bookworm (security)
5.7-2+deb12u6
fixed
bullseye
vulnerable
bullseye (security)
4.13-10+deb11u7
fixed
forky
7.6-2
fixed
sid
7.6-2
fixed
trixie
6.13-2+deb13u2
fixed
trixie (security)
6.13-2+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
focal
needs-triage
jammy
Fixed 5.9-0ubuntu0.22.04.7
released
noble
Fixed 6.14-0ubuntu0.24.04.4
released
questing
Fixed 6.14-0ubuntu0.25.10.4
released
resolute
Fixed 7.2-2ubuntu2.2
released
squid3
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
squid
Azure Linux 3.0
0:6.13-5.azl3
fixed