Vulnerability record · CVE-2005-0095 · published 15 January 2005
CVE-2005-0095: Squid WCCP message parsing denial of service
Squid · Squid
Squid 2.5.STABLE7 and earlier mishandles malformed WCCP messages, allowing a remote attacker to crash the proxy. The flaw lies in the WCCP message parsing code, which fails to validate WCCP_I_SEE_YOU cache numbers and accepts spoofed source addresses referencing Squid's home router. Because Squid is often an internet-facing proxy, a crash can disrupt web access for all users behind it.
Description
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is a remote unauthenticated denial of service with public exploit material and high EPSS, but it only affects availability and requires source address spoofing.
What it is
Squid 2.5.STABLE7 and earlier mishandles malformed WCCP messages, allowing a remote attacker to crash the proxy. The flaw lies in the WCCP message parsing code, which fails to validate WCCP_I_SEE_YOU cache numbers and accepts spoofed source addresses referencing Squid's home router. Because Squid is often an internet-facing proxy, a crash can disrupt web access for all users behind it.
Impact
An attacker can cause a denial of service by crashing the Squid process, interrupting proxied web traffic. No data confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
Reachable over the network via WCCP messages sent to the Squid host, with no authentication required. The description indicates the source address must be spoofed to match Squid's home router, which raises the bar for a successful attack but does not require user interaction.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high (0.688, 99.3rd percentile), and one reference is tagged Exploit, indicating public exploit material exists, though the record does not confirm active exploitation.
What to do
- Upgrade Squid to a version later than 2.5.STABLE7, or apply the vendor patch squid-2.5.STABLE7-wccp_denial_of_service.patch.
- Apply the distribution vendor updates referenced in the advisories (Red Hat, Debian, Gentoo, Novell, Mandriva, Trustix, Conectiva).
- If WCCP is not required, disable WCCP handling or block WCCP traffic at the network perimeter.
- Restrict who can send WCCP traffic to the Squid host using router and firewall ACLs, and enable anti-spoofing controls.
- Monitor Squid process restarts and crashes as an indicator of attempted or successful exploitation.
Detection
- Alert on unexpected Squid process termination or restart events on proxy hosts.
- Monitor for inbound WCCP protocol traffic to Squid hosts from unexpected or spoofed source addresses.
- Review network logs for packets claiming to originate from the Squid home router address.
- Correlate proxy availability gaps with WCCP-related traffic in firewall and router logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0095 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0095), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.