Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
https://exchange.xforce.ibmcloud.com/vulnerabilities/3433
http://www.squid-cache.org/Versions/v2/2.2/bugs/