Squid: Memory disclosure in FTP gateway
Published Jul 16, 2026
6.5
MEDIUMCVSS 3.1
EPSS 2.43%
Description
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
Affected products
-
- Version < 7.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Squid-Cache | Squid | n/a |
|
- < 7.6
No data.
Red Hat Enterprise Linux 10
squid
Fix deferred
Red Hat Enterprise Linux 6
squid
Fix deferred
Red Hat Enterprise Linux 6
squid34
Fix deferred
Red Hat Enterprise Linux 7
squid
Fix deferred
Red Hat Enterprise Linux 8
squid
Fix deferred
Red Hat Enterprise Linux 8
squid:4/squid
Fix deferred
Red Hat Enterprise Linux 9
squid
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | squid | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | squid | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | squid | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | squid | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | squid:4/squid | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | squid | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this issue, an attacker must have a valid account on the Squid proxy and must also control an FTP server reachable from the proxy on port 21. HTTPS traffic handled via CONNECT tunnels (the vast majority of modern web traffic) is opaque to the proxy because the underlying request data is encrypted and Squid does not have access to it. The impact is limited to information disclosure of cleartext HTTP request contents or traffic in TLS-terminating (SSL bump) proxy configurations where Squid decrypts and inspects traffic. FTP protocol usage has declined considerably in most environments since major browsers removed FTP support, further narrowing the practical attack surface. Due to these reasons, this vulnerability has been rated with a moderate severity.
Red Hat mitigation
When FTP access is not required, block FTP traffic at the proxy by adding the following settings to the squid.conf configuration file above any custom 'http_access allow' rules: ~~~ acl FTP proto FTP http_access deny FTP ~~~ When FTP access is required, configure Squid to only allow FTP access to specific and trusted destination domains. See the example below for restricting FTP access to the 'trusted.server.example.com' domain: ~~~ acl FTP proto FTP acl ftp_allowlist dstdomain .trusted.server.example.com http_access deny FTP !ftp_allowlist ~~~
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.43% (0.02428) | 83.64th | v5 (v2026.06.15) |
| Jul 17, 2026 | 1.91% (0.01907) | 77.43th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-47729 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492882 Issue Tracking
- https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8 x_refsource_MISCPatch
- https://github.com/squid-cache/squid/pull/2408 x_refsource_MISCPatch
- https://github.com/squid-cache/squid/pull/2409 x_refsource_MISCPatch
- https://github.com/squid-cache/squid/releases/tag/SQUID_7_6 x_refsource_MISCRelease Notes
- https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47729
- https://www.cve.org/CVERecord?id=CVE-2026-47729
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-47729 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2492882 | Issue Tracking | |
| https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8 | x_refsource_MISCPatch | |
| https://github.com/squid-cache/squid/pull/2408 | x_refsource_MISCPatch | |
| https://github.com/squid-cache/squid/pull/2409 | x_refsource_MISCPatch | |
| https://github.com/squid-cache/squid/releases/tag/SQUID_7_6 | x_refsource_MISCRelease Notes | |
| https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-47729 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-47729 |
Change history (0)
No recorded changes yet.