AI Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2024-25617
Squid vulnerability analysis and mitigation

Overview

CVE-2024-25617 (SQUID-2024:2) affects Squid, an open source caching proxy for the Web supporting HTTP, HTTPS, and FTP. The vulnerability was discovered by Joshua Rogers of Opera Software and was disclosed on February 14, 2024. This vulnerability affects Squid versions prior to 6.5 and is related to a Collapse of Data into Unsafe Value bug in HTTP header parsing (GitHub Advisory).

Technical details

The vulnerability stems from improper handling of HTTP header parsing when dealing with oversized headers in HTTP messages. The issue occurs when the request_header_max_size or reply_header_max_size settings are left at their default values (64KB) in versions prior to 6.5. The vulnerability has received a CVSS v3.1 base score of 7.5 HIGH with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H according to NVD assessment (NVD).

Impact

When successfully exploited, this vulnerability can lead to a Denial of Service (DoS) condition. The attack can be initiated by either a remote client or a remote server sending oversized headers in HTTP messages, potentially affecting the availability of the Squid proxy service (GitHub Advisory).

Exploitability

The vulnerability can be exploited remotely without requiring any authentication or user interaction. For versions prior to 6.5, exploitation is possible when the request_header_max_size or reply_header_max_size settings are left at their default values. The attack vector is network-accessible and requires low complexity to execute (NVD).

Mitigation and workarounds

For Squid versions older than 6.5, administrators can mitigate the vulnerability by adding the following configuration to squid.conf: request_header_max_size 21 KB and reply_header_max_size 21 KB. For Squid 6.5 and later, the default settings are safe, but administrators should remove any custom request_header_max_size and reply_header_max_size configurations from squid.conf. The vulnerability is fully patched in Squid version 6.5 (GitHub Advisory).

Community reactions

Various vendors have responded to this vulnerability by releasing security advisories and patches. Red Hat has classified this as an Important security issue and released updates for affected versions (Red Hat Advisory). NetApp has also acknowledged the vulnerability in their BlueXP product and released fixes in version 3.9.39 (NetApp Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

squid: 5.7-2+deb12u1

Fixed

bullseye

squid: 4.13-10+deb11u3

Fixed

sid

squid: 6.5-1

Fixed

trixie

squid: 6.5-1

Fixed

SourceThis report was generated using AI

Related Squid vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-33526CRITICAL9.2
  • Squid logoSquid
  • squid.src
NoYesMar 26, 2026
CVE-2026-32748HIGH8.7
  • Squid logoSquid
  • squid:4::squid
NoYesMar 26, 2026
CVE-2026-33515MEDIUM6.9
  • Squid logoSquid
  • squid
NoYesMar 26, 2026
CVE-2026-47729MEDIUM6.5
  • Squid logoSquid
  • squid:4::libecap-devel
NoYesJul 16, 2026
CVE-2026-50012MEDIUM5.5
  • Squid logoSquid
  • squid-debuginfo
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management