# Nearly Three Decades Later: 'Squidbleed' Exposes Cleartext HTTP Credentials Through Ancient Squid Proxy Bug
## The Threat
A critical heap over-read vulnerability in Squid web proxy, disclosed this month and named Squidbleed in honor of the infamous Heartbleed leak, can expose another user's cleartext HTTP requests—including authentication credentials and session tokens—to anyone already permitted to use the same proxy. The vulnerability traces its origins to a 1997 FTP directory-listing parser change that was never properly secured, making it one of the longest-dormant memory disclosure flaws discovered in recent years.
Researchers at Calif.io identified the flaw during security analysis and found that the bug remains active in Squid's default configuration across multiple distributions. The vulnerability allows an authenticated attacker—someone already with proxy access—to craft a malicious FTP response that triggers an unbounded memory read, pulling sensitive data from buffers that Squid reuses without zeroing. The leaked payload travels back to the attacker in what appears to be a benign FTP directory listing filename, exposing unencrypted HTTP headers that may contain Authorization tokens, session cookies, or other sensitive data.
The attack works because Squid's FTP parser contains a classic buffer over-read flaw: when parsing FTP directory listings from what the attacker controls, the code fails to properly validate null terminators. A specially crafted listing—one that ends immediately after a timestamp with no filename—causes the parser to read past the buffer boundary and into adjacent memory. Since Squid reallocates freed buffers without zeroing them, recently-processed HTTP requests remain resident in those memory regions, ready to be exfiltrated. Proof-of-concept code is now public, though no active exploitation in the wild has been reported as of press time.
## Severity and Impact
| Attribute | Detail |
|---|---|
| CVE Identifier | CVE-2026-47729 |
| CVSS v3.1 Score | 6.5 (Medium) |
| CVSS Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low (trusted proxy client) |
| User Interaction | None |
| Impact - Confidentiality | High |
| Impact - Integrity | None |
| Impact - Availability | None |
| CWE | CWE-125 (Out-of-bounds Read) |
| Affected Component | Squid FTP Gateway Parser |
The CVSS score of 6.5 reflects the bounded nature of the attack: the threat actor must already possess legitimate proxy access, making this an insider-threat scenario rather than a network-wide exposure. However, in shared network environments—schools, corporate offices, public WiFi hotspots—this boundary is easily crossed, as users routinely share the same proxy instance.
## Affected Products
Squid Web Proxy versions:
Distribution Note: Many Linux distributions, including Debian (currently packaging Squid 5.7), maintain their own backports. Verify the specific patch status in your distribution's advisory rather than relying on upstream version numbers alone.
## Mitigations
Immediate Action (Recommended):
The simplest and most effective mitigation is to disable FTP protocol support in Squid, which is a reasonable default for most modern deployments. FTP has been deprecated or removed from contemporary browsers (Chromium dropped it years ago), and most networks carry minimal or zero FTP traffic. Disabling FTP eliminates the attack surface entirely and works across all Squid versions.
To disable FTP in Squid:
ftp_passive off
ftp_epsv offAnd add deny all rules to FTP-related ACLs in squid.conf.
Patching (If FTP is Required):
If your organization depends on FTP protocol support:
FtpGateway.ccNetwork-Level Controls:
Detection:
Enable detailed Squid access logs and watch for FTP transactions returning unusually long or binary filenames, which may indicate the exploit being triggered.
## References
## HackWire Analysis
Squidbleed reveals a pattern that should concern infrastructure teams everywhere: ancient code, even code that's been around since 1997, can harbor memory safety flaws that persist undetected for decades. The fact that this vulnerability required nearly 30 years and AI-assisted analysis to surface—Calif.io credits Anthropic's Claude model with identifying the strchr quirk—suggests that manual code audits and conventional security testing may have simply missed it. The researchers note this parser bug is part of a broader trend of AI agents uncovering buried vulnerabilities in legacy parsers, from FFmpeg to other widely-used libraries.
What makes Squidbleed particularly dangerous is its context. Squid typically lives at the nexus of trust: shared office networks, school systems, and public WiFi providers all rely on it. In these environments, the attacker and victim don't have to be sophisticated adversaries—they're just peers on the same network. A malicious student on a school network, a disgruntled employee, or a guest on corporate WiFi can exfiltrate Authorization headers and session tokens from colleagues simply by setting up an FTP server they control. The leaked credentials aren't hypothetical; proof-of-concept code demonstrates real credential theft.
The irony is that the fix is trivial—a null-terminator check before the vulnerable strchr calls—yet its absence persisted for nearly three decades. This should serve as a sobering reminder that complexity isn't required for dangerous bugs; sometimes the oldest, simplest code is the most dangerous precisely because no one re-examines it.
The practical takeaway is urgent and clean: disable FTP. There is almost no legitimate reason to enable FTP in a modern Squid deployment, and disabling it removes the attack surface without waiting for patching cycles or distribution backports. Organizations should audit their proxy configurations immediately and treat FTP as a legacy protocol that belongs in the history books, not on the internet.
— *HackWire Editorial*
## Related Coverage