Vulnerability record · CVE-2021-28662 · published 27 May 2021
CVE-2021-28662: Squid proxy denial of service via crafted response header
Squid Cache · Squid
Squid 4.x before 4.15 and 5.x before 5.0.6 can be crashed by a remote server that returns a certain response header over HTTP or HTTPS. Because the triggering header can plausibly appear in benign traffic, the flaw can be hit without deliberate attacker action, making it a reliability risk for any proxy deployment in the affected ranges.
Description
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Automated analysis
high priorityAvailability-only impact, but a very high EPSS score and trivially reachable network path make this a realistic operational risk for unpatched Squid proxies.
What it is
Squid 4.x before 4.15 and 5.x before 5.0.6 can be crashed by a remote server that returns a certain response header over HTTP or HTTPS. Because the triggering header can plausibly appear in benign traffic, the flaw can be hit without deliberate attacker action, making it a reliability risk for any proxy deployment in the affected ranges.
Impact
An attacker or even an ordinary upstream server can cause a denial of service on the Squid proxy, disrupting web access for all clients that rely on it. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reached over the network when Squid processes a response from a remote origin server; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), meaning a client must trigger the request that pulls in the malicious or malformed header. No authentication to Squid itself is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.7176, ~99.4th percentile), indicating elevated likelihood of exploitation activity. Patch and vendor advisory references are present.
What to do
- Upgrade Squid to 4.15 or later on the 4.x branch, or 5.0.6 or later on the 5.x branch, or to the fixed 6.x changeset.
- Apply the distribution packages from Debian (DSA-4924) and Fedora advisories if you rely on packaged builds.
- Restrict or monitor outbound proxy traffic to reduce exposure to untrusted origin servers where feasible.
- Plan for proxy restart or failover capacity so a crash does not take all egress traffic down.
Detection
- Monitor Squid process crashes, core dumps and unexpected restarts, correlating them with upstream response headers.
- Alert on abrupt drops in proxy request throughput or client connection failures that coincide with specific origin servers.
- Review Squid cache and access logs around crash times for unusual or malformed response headers from upstream hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-28662 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28662), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.