Vulnerability record · CVE-2005-0241 · published 2 May 2005
CVE-2005-0241: Squid httpProcessReplyHeader mishandles oversized HTTP reply headers
Squid · Squid
Squid 2.5-STABLE7 and earlier fails to properly set the debug context in httpProcessReplyHeader when handling oversized HTTP reply headers. This can let a remote attacker poison the cache or bypass access controls that rely on header size. The record is old and thin, with no CWE mapping beyond 'Other' and no affected-version detail beyond the stated release.
Description
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 rates it MEDIUM with integrity-only impact, but the high EPSS and cache-poisoning potential warrant attention on any still-running Squid 2.5-STABLE7 or earlier.
What it is
Squid 2.5-STABLE7 and earlier fails to properly set the debug context in httpProcessReplyHeader when handling oversized HTTP reply headers. This can let a remote attacker poison the cache or bypass access controls that rely on header size. The record is old and thin, with no CWE mapping beyond 'Other' and no affected-version detail beyond the stated release.
Impact
An attacker may be able to inject or alter cached content and evade header-size-based access controls. The CVSS vector shows integrity impact only, with no confidentiality or availability impact.
Attack surface
Reachable over the network via HTTP traffic processed by the Squid proxy; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high at 0.69661 (99.3rd percentile), but references are patch and advisory links only, with no public exploit tag.
What to do
- Upgrade Squid past 2.5-STABLE7 to a fixed release; the vendor patch is referenced at squid-cache.org.
- Apply the vendor or distribution patches (Red Hat RHSA-2005-060/061, Novell, Conectiva) if upgrading is not immediately possible.
- Restrict who can send HTTP requests through the proxy to trusted clients where feasible.
- Review cache and access-control rules that depend on header size, since those checks may be bypassable.
Detection
- Inspect Squid cache.log and access.log for oversized HTTP reply headers or abnormal header sizes.
- Monitor for unexpected cache content changes or cache poisoning indicators on the proxy.
- Alert on access-control decisions that appear inconsistent with configured header-size limits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0241 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.