Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2019-12519
Squid vulnerability analysis and mitigation

Overview

An issue was discovered in Squid through version 4.7 affecting the Edge Side Includes (ESI) functionality. When handling the 'esi:when' tag with ESI enabled, Squid calls ESIExpression::Evaluate function which uses a fixed stack buffer to hold expressions during evaluation. The vulnerability exists because there is no check to ensure the stack won't overflow when adding new members during expression processing (NVD, OSS Security).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue specifically occurs in the ESIExpression::Evaluate function where a fixed stack buffer is used without proper bounds checking. When processing expressions, the function either evaluates the top of the stack or adds new members, but lacks overflow protection mechanisms (NetApp Security).

Impact

The vulnerability can lead to multiple severe impacts including cache poisoning, remote code execution, and denial of service. On systems with heap overflow protection, the overflow will cause the proxy to shutdown, resulting in denial of service for all clients. On systems with ESI buffer pooling (the default configuration), the overflow will truncate portions of generated payloads, potentially poisoning the HTTP response cache with corrupted objects. Additionally, the vulnerability allows attackers to overwrite arbitrary attacker-controlled information onto the process stack, enabling remote code execution with specially crafted ESI payloads (OSS Security).

Exploitability

The vulnerability requires an attacker to control an upstream server or compromise the transmission channel to deliver malicious ESI response syntax. The attack vector is network-accessible with low attack complexity, requiring no privileges or user interaction (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Squid versions 4.11 and 5.0.2. For systems that cannot immediately update, a workaround is available by building Squid with the '--disable-esi' configuration option to disable ESI functionality. Various Linux distributions have also released security updates including Ubuntu, Debian, and OpenSUSE (Ubuntu Security, Debian Security, OpenSUSE Security).

Additional resources


SourceThis report was generated using AI

Related Squid vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-33526CRITICAL9.2
  • Squid logoSquid
  • squid3
NoYesMar 26, 2026
CVE-2026-47729MEDIUM6.5
  • Squid logoSquid
  • squid-debuginfo
NoYesJul 16, 2026
CVE-2026-50012MEDIUM5.5
  • Squid logoSquid
  • libecap
NoYesJul 16, 2026
CVE-2026-62846NONEN/A
  • Squid logoSquid
  • squid
NoYesSep 17, 2026
CVE-2026-61642NONEN/A
  • Squid logoSquid
  • squid3
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management