Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Squid-cache
Squid-cache squid |
|
Vendors & Products |
Squid-cache
Squid-cache squid |
Sat, 02 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 01 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions. | |
Title | Squid's URN Handling can lead to Buffer Overflow | |
Weaknesses | CWE-122 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-01T18:02:19.117Z
Updated: 2025-08-01T18:43:46.346Z
Reserved: 2025-07-25T16:19:16.091Z
Link: CVE-2025-54574

Updated: 2025-08-01T18:43:38.829Z

Status : Awaiting Analysis
Published: 2025-08-01T18:15:55.390
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-54574
