Squid < 7.6 Heap-based Buffer Overflow

critical Nessus Plugin ID 321511

Synopsis

The remote proxy server is affected by a heap-based buffer overflow vulnerability.

Description

The version of Squid on the remote host is prior to 7.6. It is, therefore, affected by a heap-based buffer overflow vulnerability:

- Due to an Improper Input Validation bug, Squid is vulnerable to a Heap-based Buffer Overflow attack against cache digests. This problem allows a trusted server to perform a Heap-based Buffer Overflow when sending maliciously crafted replies to cache_digest request messages. This attack is limited to Squid instances that have been compiled with the --enable-cache-digests option. (CVE-2026-50012)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Squid version 7.6 or later.

See Also

https://seclists.org/oss-sec/2026/q2/896

http://www.nessus.org/u?c99d5d24

Plugin Details

Severity: Critical

ID: 321511

File Name: squid_7_6.nasl

Version: 1.1

Type: Remote

Family: Firewalls

Published: 6/18/2026

Updated: 6/18/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2026-50012

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Vulnerability Information

CPE: cpe:/a:squid-cache:squid

Required KB Items: Settings/ParanoidReport, installed_sw/Squid

Patch Publication Date: 6/8/2026

Vulnerability Publication Date: 6/12/2026

Reference Information

CVE: CVE-2026-50012