Vulnerability record · CVE-2016-4054 · published 25 April 2016
CVE-2016-4054: Squid proxy buffer overflow via crafted ESI responses
Canonical · Ubuntu Linux
Squid 3.x before 3.5.17 and 4.x before 4.0.9 contain a buffer overflow (CWE-119) triggered by crafted Edge Side Includes (ESI) responses. A remote attacker can corrupt memory in the proxy process, which matters because Squid is typically an internet-facing caching proxy. The record does not state whether ESI processing must be enabled for the flaw to be reachable.
Description
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote, unauthenticated code execution in an internet-facing proxy with a very high EPSS score, though the High attack complexity and absence of KEV listing temper it below critical.
What it is
Squid 3.x before 3.5.17 and 4.x before 4.0.9 contain a buffer overflow (CWE-119) triggered by crafted Edge Side Includes (ESI) responses. A remote attacker can corrupt memory in the proxy process, which matters because Squid is typically an internet-facing caching proxy. The record does not state whether ESI processing must be enabled for the flaw to be reachable.
Impact
Successful exploitation can lead to arbitrary code execution in the context of the Squid process, giving the attacker control of the proxy. The CVSS 3.0 vector rates confidentiality, integrity and availability impact all High.
Attack surface
Reachable over the network (AV:N) with no privileges and no user interaction (PR:N, UI:N), via a crafted ESI response delivered to the proxy. The High attack complexity (AC:H) indicates conditions beyond the attacker's control must align for the overflow to succeed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.776 (99.5th percentile), indicating substantial predicted exploitation activity. Reference tags are advisory and release-note only; no public exploit or PoC is cited in the record.
What to do
- Upgrade Squid to 3.5.17 or later in the 3.x line, or 4.0.9 or later in the 4.x line, per the vendor advisory SQUID-2016_6.
- Apply distribution backports (Ubuntu USN-2995-1, Debian DSA-3625, Red Hat RHSA-2016:1138/1139/1140, Gentoo GLSA 201607-01, openSUSE advisories) where a full upgrade is not possible.
- Disable ESI processing if it is not required, since the flaw is reached through ESI responses.
- Restrict who can supply responses to the proxy and limit proxy exposure to untrusted networks where feasible.
Detection
- Monitor Squid process crashes or restarts and correlate them with ESI-containing responses in proxy logs.
- Search proxy and upstream logs for ESI markup in responses from untrusted or unexpected origins.
- Alert on anomalous child process exits or core dumps from the Squid service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4054 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4054), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.