← volver
CVE-2026-47729mediumCWE-125CWE-1289

Squid: Memory disclosure in FTP gateway

33Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 6.5epss 1.5%
de la publicación al arma0 días
Publicada en NVD16 jul
1ª PoC21 jun
probabilidad de explotación
1.5%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
squid-cache · squid
PoCs públicas encontradas1
githubgithub.com/0xBlackash/CVE-2026-477295
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.