← Vulnerability feed

Vulnerability record · CVE-2024-23638 · published 24 January 2024

CVE-2024-23638: Squid expired pointer reference causes Cache Manager DoS

Squid Cache · Squid

Squid versions before 6.6 contain an expired pointer reference bug that crashes the proxy when generating error pages for Cache Manager reports. A trusted client can trigger a denial of service against the Cache Manager error response path. The flaw is fixed in Squid 6.6, with patches available for stable releases.

6.5 CVSS 3.1 Medium EPSS 60% · top 0.9% CWE-825 · CWE-825CWE-672 · CWE-672
6.5CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS 6.5 medium severity with availability-only impact, but high EPSS and a public exploit reference raise the urgency for exposed Squid deployments.

What it is

Squid versions before 6.6 contain an expired pointer reference bug that crashes the proxy when generating error pages for Cache Manager reports. A trusted client can trigger a denial of service against the Cache Manager error response path. The flaw is fixed in Squid 6.6, with patches available for stable releases.

Impact

An attacker with trusted client access can crash Squid, disrupting proxy service for all users relying on it. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

Reachable over the network via the Cache Manager interface, which requires the attacker to be a trusted client (authenticated or otherwise permitted by Squid ACLs). No user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6005 (99.09th percentile), indicating high predicted exploitation activity. A public exploit reference is tagged in the advisory, though no confirmed in-the-wild exploitation is stated.

What to do

  • Upgrade Squid to version 6.6 or later.
  • Apply the vendor patches for Squid 5.x and 6.x stable releases if immediate upgrade is not possible.
  • Restrict Cache Manager access with 'http_access deny manager' as a workaround.
  • Limit trusted client access to the proxy to only necessary hosts and users.
  • Monitor Squid logs for repeated Cache Manager error responses or crashes.

Detection

  • Monitor Squid process crashes or restarts correlated with Cache Manager requests.
  • Alert on repeated requests to the Cache Manager interface (e.g., /squid-internal-mgr/) from a single client.
  • Review Squid access logs for error page generation patterns tied to Cache Manager reports.
  • Track EPSS and vendor advisories for updated exploitation intelligence.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.squid-cache.org/Versions/v5/SQUID-2023_11.patch Mailing ListPatch
http://www.squid-cache.org/Versions/v6/SQUID-2023_11.patch Mailing ListPatch
https://github.com/squid-cache/squid/commit/290ae202883ac28a48867079c2fb34c40efd382b Patch
https://github.com/squid-cache/squid/commit/e8118a7381213f5cfcdeb4cec1d2d854bfd261c8 Patch
https://github.com/squid-cache/squid/security/advisories/GHSA-j49p-553x-48rx Vendor Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/7R4KPSO3MQT3KAOZV7LC2GG3C
https://lists.fedoraproject.org/archives/list/[email protected]/message/XWQHRDRHDM5PQTU6BHH4C5KGL
https://megamansec.github.io/Squid-Security-Audit/stream-assert.html Exploit
https://security.netapp.com/advisory/ntap-20240208-0010/
http://www.squid-cache.org/Versions/v5/SQUID-2023_11.patch Mailing ListPatch
http://www.squid-cache.org/Versions/v6/SQUID-2023_11.patch Mailing ListPatch
https://github.com/squid-cache/squid/commit/290ae202883ac28a48867079c2fb34c40efd382b Patch
https://github.com/squid-cache/squid/commit/e8118a7381213f5cfcdeb4cec1d2d854bfd261c8 Patch
https://github.com/squid-cache/squid/security/advisories/GHSA-j49p-553x-48rx Vendor Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/7R4KPSO3MQT3KAOZV7LC2GG3C
https://lists.fedoraproject.org/archives/list/[email protected]/message/XWQHRDRHDM5PQTU6BHH4C5KGL
https://megamansec.github.io/Squid-Security-Audit/stream-assert.html Exploit
https://security.netapp.com/advisory/ntap-20240208-0010/

Track CVE-2024-23638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54574Squid-cache squid heap-based buffer overflow vulnerabilitySquid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution att…EPSS 23%9.8CVE-2020-11945Squid-cache squid integer overflow vulnerabilityAn issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar…EPSS 27%9.8CVE-2019-12519Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function …EPSS 6.7%9.8CVE-2019-12524Squid-cache squid missing authentication for critical function vulnerabilityAn issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid…EPSS 4.3%9.8CVE-2019-12526Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a rem…EPSS 20%9.8CVE-2019-12525Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the heade…EPSS 24%9.2CVE-2026-33526Squid-cache squid use after free vulnerabilitySquid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP tr…EPSS 13%9.1CVE-2019-12523Squid-cache squid vulnerabilityAn issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through …EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2024-23638), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.