Denial of Service in HTTP Header parser in squid proxy
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Squid proxy can crash when processing very large HTTP headers sent by remote clients or servers. This causes the proxy to stop working temporarily, disrupting web access for all users relying on it.
A Collapse of Data into Unsafe Value flaw in Squid's HTTP header parser allows remote attackers to trigger a Denial of Service by sending oversized headers exceeding request_header_max_size or reply_header_max_size limits. Affected versions prior to 6.5 use unsafe default values; exploitation requires no authentication and impacts proxy availability.