← Vulnerability feed

Vulnerability record · CVE-2005-0174 · published 7 February 2005

CVE-2005-0174: Squid proxy HTTP header parsing flaw enables cache poisoning

Squid · Squid

Squid 2.5 through 2.5.STABLE7 mishandles HTTP headers that violate the specification, including multiple Content-Length headers, bare carriage return characters, and header names containing whitespace. Because the proxy accepts malformed headers, a remote attacker can poison cached responses or conduct related attacks against downstream users. The record does not specify the exact downstream impact beyond cache poisoning and unspecified attacks.

5.0 CVSS 2.0 Medium EPSS 50% · top 1.1%
5.0CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable without authentication and has a very high EPSS score, though it is not in KEV and the CVSS impact is limited to integrity.

What it is

Squid 2.5 through 2.5.STABLE7 mishandles HTTP headers that violate the specification, including multiple Content-Length headers, bare carriage return characters, and header names containing whitespace. Because the proxy accepts malformed headers, a remote attacker can poison cached responses or conduct related attacks against downstream users. The record does not specify the exact downstream impact beyond cache poisoning and unspecified attacks.

Impact

An attacker can inject or corrupt content in the Squid cache, causing other users to receive attacker-controlled or altered responses. The CVSS vector shows integrity impact only, with no confidentiality or availability impact recorded.

Attack surface

Reachable over the network by sending crafted HTTP requests to the Squid proxy; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is in header parsing, so any client able to send requests through or to the proxy can trigger it.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.50 probability (98.9th percentile), and references include vendor advisories and Red Hat patch errata. No public exploit code is cited in the record.

What to do

  • Upgrade Squid past 2.5.STABLE7 to a release with corrected header parsing, per the vendor advisory.
  • Apply the Red Hat errata RHSA-2005-060 and RHSA-2005-061 or the equivalent distribution patch for your platform.
  • Restrict who can send requests through the proxy to trusted networks where feasible.
  • Monitor vendor advisories for any further header-parsing fixes in the 2.5 branch.

Detection

  • Inspect proxy logs for requests containing multiple Content-Length headers or header names with embedded whitespace.
  • Search for bare carriage return bytes in HTTP request headers reaching the proxy.
  • Alert on cache entries whose stored content does not match the origin response for the same URL.
  • Correlate repeated malformed-header requests from a single source with subsequent cache anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Vendor Advisory
http://fedoranews.org/updates/FEDORA--.shtml
http://marc.info/?l=bugtraq&m=110780531820947&w=2
http://www.kb.cert.org/vuls/id/768702 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2005:034
http://www.novell.com/linux/security/advisories/2005_06_squid.html Vendor Advisory
http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
http://www.redhat.com/support/errata/RHSA-2005-060.html Patch
http://www.redhat.com/support/errata/RHSA-2005-061.html Patch
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing Vendor Advisory
http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10656
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Vendor Advisory
http://fedoranews.org/updates/FEDORA--.shtml
http://marc.info/?l=bugtraq&m=110780531820947&w=2
http://www.kb.cert.org/vuls/id/768702 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2005:034
http://www.novell.com/linux/security/advisories/2005_06_squid.html Vendor Advisory
http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
http://www.redhat.com/support/errata/RHSA-2005-060.html Patch
http://www.redhat.com/support/errata/RHSA-2005-061.html Patch
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing Vendor Advisory
http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10656

Track CVE-2005-0174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-0194Squid vulnerabilitySquid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, …EPSS 5.1%7.5CVE-2005-1711Clam anti-virus clamav vulnerabilityGibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which do…EPSS 1.0%7.5CVE-2005-0173Squid vulnerabilitysquid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a…EPSS 32%7.5CVE-2005-1345Squid vulnerabilitySquid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could…EPSS 1.7%7.5CVE-2004-0189Squid vulnerabilityThe "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charac…EPSS 14%7.5CVE-2002-0713Squid vulnerabilityBuffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via …EPSS 5.5%7.5CVE-2002-0714Squid vulnerabilityFTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote atta…EPSS 2.7%7.5CVE-2002-0163Squid vulnerabilityHeap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a …EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2005-0174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.