Back

CRITICAL

Squid's URN Handling can lead to Buffer Overflow

Published Aug 1, 2025

Description

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

Affected products

Remediation

Red Hat statement

This vulnerability is Important because the heap-based buffer overflow occurs during URN processing in Squid’s core request-handling path, which is exposed to untrusted, remote input. Unlike flaws that merely cause a service crash, this defect allows an attacker to manipulate heap memory structures, potentially achieving arbitrary code execution within the Squid process context. Since Squid often runs with elevated privileges and serves as a gateway between internal and external networks, successful exploitation could provide a remote attacker with direct control over the proxy server, enabling them to pivot into internal systems, intercept sensitive traffic, or alter cached content.

Red Hat mitigation

Users can disable URN access permissions to mitigate this issue.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 1, 2025
Updated Nov 5, 2025
Reserved Jul 25, 2025
CISA Vulnrichment
Updated Aug 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 1, 2025