CVE-2026-47729
Published:June 15, 2026
Updated:June 15, 2026
Out-of-bounds read in Squid FTP gateway. Improper input validation allows a trusted client to trigger an out-of-bounds read from unrelated transactions when accessing a misbehaving FTP server through Squid's FTP gateway, potentially exposing memory from concurrent sessions. Fixed in Squid 7.7.
Affected Packages
https://github.com/squid-cache/squid.git (GITHUB):
Affected version(s) >=SQUID_3_0_RC1 <SQUID_7_6Fix Suggestion:
Update to version SQUID_7_6Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
2.3
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
3.1
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE