Vulnerability record · CVE-2023-46847 · published 3 November 2023
CVE-2023-46847: Squid HTTP Digest Authentication heap buffer overflow DoS
Squid Cache · Squid
Squid contains a classic buffer overflow (CWE-120) that lets a remote attacker write up to 2 MB of arbitrary data to heap memory when the proxy is configured to accept HTTP Digest Authentication. Because the flaw is reachable over the network without credentials, it can crash or destabilize the proxy, disrupting all traffic that depends on it.
Description
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network-reachable, unauthenticated availability impact and a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Squid contains a classic buffer overflow (CWE-120) that lets a remote attacker write up to 2 MB of arbitrary data to heap memory when the proxy is configured to accept HTTP Digest Authentication. Because the flaw is reachable over the network without credentials, it can crash or destabilize the proxy, disrupting all traffic that depends on it.
Impact
An attacker can corrupt heap memory and cause a denial of service, taking down the Squid proxy and any services routed through it. The record describes only availability impact; no confidentiality or integrity gain is stated.
Attack surface
Reached over the network via HTTP requests to a Squid instance configured for HTTP Digest Authentication, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.88351 (99.763rd percentile), indicating strong predicted exploitation activity; references are vendor and Red Hat advisories only, with no public exploit tag.
What to do
- Apply the Squid vendor fix and the relevant Red Hat errata (RHSA-2023:6266 through RHSA-2023:7578) as soon as possible.
- If patching cannot be immediate, disable HTTP Digest Authentication on Squid and use an alternative authentication scheme.
- Restrict network access to Squid proxy ports to trusted clients only.
- Monitor Squid processes for crashes or restarts and treat repeated failures as potential attack activity.
Detection
- Alert on Squid process crashes, core dumps or unexpected restarts, especially correlated with inbound proxy requests.
- Inspect proxy logs for malformed or oversized HTTP Digest Authentication headers and repeated authentication failures from single sources.
- Baseline normal Digest Authentication request sizes and flag anomalous large payloads to the proxy.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-46847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.