CVE-2023-46724
Squid vulnerability analysis and mitigation

Overview

CVE-2023-46724 affects Squid, a caching proxy for the Web. The vulnerability was discovered in versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 that were compiled using --with-openssl. The issue was disclosed in November 2023 and involves an Improper Validation of Specified Index bug in SSL Certificate validation (Vendor Advisory).

Technical details

The vulnerability stems from an Improper Validation of Specified Index bug that affects SSL Certificate validation in Squid. The issue received a CVSS v3.1 base score of 8.6 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H. The vulnerability specifically affects installations compiled with SSL support using the --with-openssl configuration option (Vendor Advisory).

Impact

When successfully exploited, this vulnerability allows a remote server to perform a Denial of Service (DoS) attack against the Squid Proxy. The attack vector is specifically limited to HTTPS and SSL-Bump operations, where an attacker can initiate a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain (Vendor Advisory).

Mitigation and workarounds

There are two primary mitigation options available: 1) Disable SSL-Bump features by removing all ssl-bump options from httpport and httpsport configurations and removing all ssl_bump directives from squid.conf, or 2) Rebuild Squid using --without-openssl. The vulnerability has been fixed in Squid version 6.4, and patches are available for stable releases in the patch archives (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Squid vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-54574CRITICAL9.8
  • SquidSquid
  • squid-migration-script
NoYesAug 01, 2025
CVE-2025-62168HIGH7.5
  • SquidSquid
  • squid-debuginfo
NoYesOct 17, 2025
CVE-2024-45802HIGH7.5
  • SquidSquid
  • libecap
NoYesOct 28, 2024
CVE-2025-59362MEDIUM4
  • SquidSquid
  • squid-debuginfo
NoYesSep 26, 2025
ELSA-2025-20935HIGHN/A
  • SquidSquid
  • squid
NoYesNov 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management