Vulnerability record · CVE-2023-49285 · published 4 December 2023
CVE-2023-49285: Squid HTTP message processing buffer overread denial of service
Squid Cache · Squid
Squid contains an out-of-bounds read (CWE-125/CWE-126) in its HTTP message processing path. A remote, unauthenticated attacker can trigger the overread and cause a denial of service against the proxy. The flaw is fixed in Squid 6.5, and the vendor states there are no known workarounds.
Description
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated denial of service with a CVSS of 7.5 and very high EPSS, though no KEV listing or documented exploitation.
What it is
Squid contains an out-of-bounds read (CWE-125/CWE-126) in its HTTP message processing path. A remote, unauthenticated attacker can trigger the overread and cause a denial of service against the proxy. The flaw is fixed in Squid 6.5, and the vendor states there are no known workarounds.
Impact
An attacker can crash or otherwise disrupt Squid HTTP message processing, denying proxy service to legitimate users. The CVSS vector shows no confidentiality or integrity impact, only availability (A:H).
Attack surface
Reachable over the network via HTTP message processing (AV:N, PR:N, UI:N), so no authentication or user interaction is required. Any client able to send requests to the Squid proxy can attempt to trigger the overread.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.88144, 99.759th percentile), indicating elevated predicted exploitation likelihood. References include patch commits and a vendor advisory, but no public exploit is cited in the record.
What to do
- Upgrade Squid to version 6.5 or later, which contains the fix.
- Apply the vendor patch commits (77b3fb4df0f126784d5fd4967c28ed40eb8d521b, deee944f9a12c9fd399ce52f3e2526bb573a9470) if an immediate upgrade is not possible.
- Track distribution backports (Debian LTS, Fedora, NetApp advisories) and apply the corresponding package updates.
- Restrict network access to the Squid proxy to trusted clients only, since no workaround exists.
- Monitor Squid processes for unexpected crashes or restarts and treat repeated failures as potential exploitation attempts.
Detection
- Monitor Squid logs and system logs for crashes, core dumps, or unexpected process restarts.
- Alert on abnormal volumes of malformed or oversized HTTP requests reaching the proxy.
- Track Squid version inventory to identify hosts still running versions below 6.5.
- Correlate proxy availability drops with inbound request patterns to spot denial-of-service attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-49285 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-49285), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.