Vulnerability record · CVE-2024-23638 · published 24 January 2024
CVE-2024-23638: Squid expired pointer reference causes Cache Manager DoS
Squid Cache · Squid
Squid versions before 6.6 contain an expired pointer reference bug that crashes the proxy when generating error pages for Cache Manager reports. A trusted client can trigger a denial of service against the Cache Manager error response path. The flaw is fixed in Squid 6.6, with patches available for stable releases.
Description
Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityCVSS 6.5 medium severity with availability-only impact, but high EPSS and a public exploit reference raise the urgency for exposed Squid deployments.
What it is
Squid versions before 6.6 contain an expired pointer reference bug that crashes the proxy when generating error pages for Cache Manager reports. A trusted client can trigger a denial of service against the Cache Manager error response path. The flaw is fixed in Squid 6.6, with patches available for stable releases.
Impact
An attacker with trusted client access can crash Squid, disrupting proxy service for all users relying on it. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network via the Cache Manager interface, which requires the attacker to be a trusted client (authenticated or otherwise permitted by Squid ACLs). No user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.6005 (99.09th percentile), indicating high predicted exploitation activity. A public exploit reference is tagged in the advisory, though no confirmed in-the-wild exploitation is stated.
What to do
- Upgrade Squid to version 6.6 or later.
- Apply the vendor patches for Squid 5.x and 6.x stable releases if immediate upgrade is not possible.
- Restrict Cache Manager access with 'http_access deny manager' as a workaround.
- Limit trusted client access to the proxy to only necessary hosts and users.
- Monitor Squid logs for repeated Cache Manager error responses or crashes.
Detection
- Monitor Squid process crashes or restarts correlated with Cache Manager requests.
- Alert on repeated requests to the Cache Manager interface (e.g., /squid-internal-mgr/) from a single client.
- Review Squid access logs for error page generation patterns tied to Cache Manager reports.
- Track EPSS and vendor advisories for updated exploitation intelligence.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-23638 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23638), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.