Stack-based buffer overflow in Squid - #VU149501
Published: September 14, 2026
Vulnerability details
The vulnerability allows a local privileged user to modify data or cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in ICAP authentication when processing user= and password= credential annotations for an ICAP service. A local privileged user can pass excessively long credentials through these annotations to modify data or cause a denial of service.
Exploitation requires Squid to be configured to use an ICAP server in conjunction with a misbehaving external ACL authentication helper.