Vulnerability record · CVE-2005-0174 · published 7 February 2005
CVE-2005-0174: Squid proxy HTTP header parsing flaw enables cache poisoning
Squid · Squid
Squid 2.5 through 2.5.STABLE7 mishandles HTTP headers that violate the specification, including multiple Content-Length headers, bare carriage return characters, and header names containing whitespace. Because the proxy accepts malformed headers, a remote attacker can poison cached responses or conduct related attacks against downstream users. The record does not specify the exact downstream impact beyond cache poisoning and unspecified attacks.
Description
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication and has a very high EPSS score, though it is not in KEV and the CVSS impact is limited to integrity.
What it is
Squid 2.5 through 2.5.STABLE7 mishandles HTTP headers that violate the specification, including multiple Content-Length headers, bare carriage return characters, and header names containing whitespace. Because the proxy accepts malformed headers, a remote attacker can poison cached responses or conduct related attacks against downstream users. The record does not specify the exact downstream impact beyond cache poisoning and unspecified attacks.
Impact
An attacker can inject or corrupt content in the Squid cache, causing other users to receive attacker-controlled or altered responses. The CVSS vector shows integrity impact only, with no confidentiality or availability impact recorded.
Attack surface
Reachable over the network by sending crafted HTTP requests to the Squid proxy; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is in header parsing, so any client able to send requests through or to the proxy can trigger it.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.50 probability (98.9th percentile), and references include vendor advisories and Red Hat patch errata. No public exploit code is cited in the record.
What to do
- Upgrade Squid past 2.5.STABLE7 to a release with corrected header parsing, per the vendor advisory.
- Apply the Red Hat errata RHSA-2005-060 and RHSA-2005-061 or the equivalent distribution patch for your platform.
- Restrict who can send requests through the proxy to trusted networks where feasible.
- Monitor vendor advisories for any further header-parsing fixes in the 2.5 branch.
Detection
- Inspect proxy logs for requests containing multiple Content-Length headers or header names with embedded whitespace.
- Search for bare carriage return bytes in HTTP request headers reaching the proxy.
- Alert on cache entries whose stored content does not match the origin response for the same URL.
- Correlate repeated malformed-header requests from a single source with subsequent cache anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.