Stack-based buffer overflow in Squid - #VU149502
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to perform an out-of-bounds write.
The vulnerability exists due to a stack-based buffer overflow in HTTP authentication when forwarding traffic to a cache_peer configured to use client-provided Basic authentication credentials. A remote user can provide Basic authentication credentials to perform an out-of-bounds write.