Out-of-bounds read in Squid - CVE-2026-47729
Published: June 24, 2026
Squid
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper validation of syntactic correctness of input in the FTP gateway when accessing a misbehaving FTP server through the gateway feature. A remote user can access a misbehaving FTP server through the gateway feature to disclose sensitive information.
The issue can cause an out-of-bounds read from random unrelated transactions.