Vulnerability record · CVE-2009-0478 · published 8 February 2009
CVE-2009-0478: Squid proxy assertion crash via invalid HTTP version number
Squid · Squid
Squid versions 2.7 through 2.7.STABLE5, 3.0 through 3.0.STABLE12, and 3.1 through 3.1.0.4 fail to properly validate the HTTP version number in a request, triggering a reachable assertion in HttpMsg.c and HttpStatusLine.c. A remote attacker can crash the proxy process, disrupting web access for all users relying on it.
Description
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote denial of service with public exploit code and very high EPSS, though impact is limited to availability and the affected versions are long outdated.
What it is
Squid versions 2.7 through 2.7.STABLE5, 3.0 through 3.0.STABLE12, and 3.1 through 3.1.0.4 fail to properly validate the HTTP version number in a request, triggering a reachable assertion in HttpMsg.c and HttpStatusLine.c. A remote attacker can crash the proxy process, disrupting web access for all users relying on it.
Impact
An unauthenticated remote attacker can cause a denial of service by crashing the Squid process; no data confidentiality or integrity impact is described, only availability loss.
Attack surface
Reachable over the network by sending a crafted HTTP request with an invalid version number to the Squid proxy listener; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71986, 99.4th percentile) and public references include an Exploit-DB entry and a SecurityFocus BID tagged Exploit and Patch, indicating public exploit code exists.
What to do
- Upgrade Squid to a version later than 2.7.STABLE5, 3.0.STABLE12, or 3.1.0.4, or apply the vendor patch referenced in SQUID-2009_1 and changeset 12432.
- If immediate upgrade is not possible, restrict proxy access to trusted networks and monitor for malformed HTTP version strings.
- Apply distribution vendor updates (openSUSE, Gentoo, Mandriva, Red Hat) where Squid is packaged.
- Consider running Squid under a supervisor that restarts the process on crash to limit downtime.
Detection
- Monitor Squid logs and process supervisor logs for assertion failures or unexpected restarts referencing HttpMsg.c or HttpStatusLine.c.
- Inspect proxy access logs for HTTP requests containing malformed or non-standard version tokens.
- Alert on repeated connection resets or 5xx responses from the proxy that correlate with a single source.
- Use network IDS signatures for HTTP requests with invalid version numbers targeting the proxy port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0478), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.