
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61642 is an HTTP Request Smuggling vulnerability in Squid proxy server, tracked as SQUID-2026:6, caused by improper enforcement of HTTP/1.1 Transfer-Encoding behavioral workflows. It affects Squid versions 3.3.0.1 through 7.5, with the fix available in version 7.6. The vulnerability was initially reported on 2026-05-29 and a patch was released on 2026-05-31, with the advisory published on 2026-09-12. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).
The root cause is classified under CWE-841 (Improper Enforcement of Behavioral Workflow) and CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling). Squid fails to properly enforce the sequencing of HTTP/1.1 Transfer-Encoding behaviors, allowing an attacker to craft ambiguous requests that are interpreted differently by Squid and upstream/downstream components. Exploitation requires network access and low-level privileges (authenticated/trusted client), with no user interaction needed and a changed scope, meaning the impact extends beyond Squid itself to upstream caches. The vulnerability was discovered by Mitchell Benjamin of Revamp Studio and fixed by Amos Jeffries of Treehouse Networks Ltd. (GitHub Advisory).
A trusted client can exploit this vulnerability to perform HTTP Request Smuggling, bypassing security controls positioned between the attacker and Squid (e.g., WAFs, access controls). When an HTTP cache operates upstream of the affected Squid instance, the attacker can additionally poison that web cache, injecting arbitrary malicious content at any URL for delivery to other clients on future requests. The primary impact is high integrity loss with no direct confidentiality or availability impact, though cache poisoning can enable secondary attacks such as phishing, malware distribution, or credential theft against downstream users (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory date. The CVE status was listed as "Reserved" at the time of Feedly ingestion (September 2026), with community discussions noting the potential severity. The attack requires low privileges (a trusted client position) and no user interaction, making it relatively accessible to internal or semi-trusted attackers. No CISA KEV listing or threat actor attribution has been identified (GitHub Advisory, Security Online).
Transfer-Encoding header that Squid and the upstream/downstream component interpret differently — for example, using Transfer-Encoding: chunked in combination with Content-Length to create a desync condition.Transfer-Encoding and Content-Length headers simultaneously, or Transfer-Encoding values with unusual whitespace/casing (e.g., Transfer-Encoding: chunked with trailing spaces); unexpected HTTP requests appearing to originate from Squid to upstream servers without a corresponding client request.The vulnerability is fixed in Squid version 7.6. For users running Squid 7.x who cannot immediately upgrade, a patch is available at the Squid project's patch archive: https://github.com/squid-cache/squid/commit/d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2.patch. The Squid project explicitly states there is no workaround for this issue — upgrading or applying the patch is the only remediation. Users of pre-packaged Squid distributions should contact their package vendor for updated packages (GitHub Advisory).
Security news outlet Security Online covered the vulnerability shortly after the advisory was published, highlighting it among Squid proxy vulnerabilities. Community briefings (e.g., workshop1.net) also noted the advisory. No major vendor statements beyond the Squid project's own advisory or notable researcher commentary beyond the credited discoverer (Mitchell Benjamin, Revamp Studio) have been identified (Security Online).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."