Vulnerability record · CVE-2024-25617 · published 14 February 2024
CVE-2024-25617: Squid HTTP header parsing denial of service via oversized headers
Squid Cache · Squid
Squid, the open source caching proxy, mishandles oversized HTTP headers due to a Collapse of Data into Unsafe Value bug in header parsing. A remote client or remote server can send oversized headers to trigger a denial of service. In Squid versions before 6.5 this works with default request_header_max_size and reply_header_max_size settings; 6.5 changed the defaults to safe values.
Description
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. In versions of Squid prior to 6.5 this can be achieved if the request_header_max_size or reply_header_max_size settings are unchanged from the default. In Squid version 6.5 and later, the default setting of these parameters is safe. Squid will emit a critical warning in cache.log if the administrator is setting these parameters to unsafe values. Squid will not at this time prevent these settings from being changed to unsafe values. Users are advised to upgrade to version 6.5. There are no known workarounds for this vulnerability. This issue is also tracked as SQUID-2024:2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 high severity with network reachability, no authentication or interaction needed, and a very high EPSS score, though impact is limited to denial of service.
What it is
Squid, the open source caching proxy, mishandles oversized HTTP headers due to a Collapse of Data into Unsafe Value bug in header parsing. A remote client or remote server can send oversized headers to trigger a denial of service. In Squid versions before 6.5 this works with default request_header_max_size and reply_header_max_size settings; 6.5 changed the defaults to safe values.
Impact
An attacker can cause a denial of service, disrupting proxy availability for all users relying on the affected Squid instance. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network by any remote client or remote server that can send HTTP messages to the proxy, with no authentication or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). Exploitation depends on the header size limits being at unsafe values, which is the default in versions prior to 6.5.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.88094 (99.758th percentile), indicating substantial predicted exploitation activity. References include patch and vendor advisory links, with no public exploit tag present in the record.
What to do
- Upgrade Squid to version 6.5 or later, which sets safe defaults for request_header_max_size and reply_header_max_size.
- If upgrade is not immediately possible, manually set request_header_max_size and reply_header_max_size to safe values and watch cache.log for the critical warning Squid emits when unsafe values are configured.
- Apply the vendor patch commit referenced in the advisory for environments that cannot move to 6.5.
- For NetApp BlueXP deployments, apply the fixes in NetApp advisory ntap-20240322-0006.
- Monitor cache.log for the critical warning about unsafe header size settings as an ongoing control.
Detection
- Alert on the Squid cache.log critical warning indicating request_header_max_size or reply_header_max_size are set to unsafe values.
- Monitor proxy availability and restart patterns for unexplained outages consistent with header-parsing resource exhaustion.
- Inspect HTTP traffic for abnormally large header blocks sent to or from the proxy.
- Track Squid version inventory to identify instances still running versions prior to 6.5.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/squid-cache/squid/commit/72a3bbd5e431597c3fdb56d752bc56b010ba3817 | PatchVendor Advisory |
| https://github.com/squid-cache/squid/security/advisories/GHSA-h5x6-w8mv-xfpr | MitigationThird Party AdvisoryVendor Advisory |
| https://security.netapp.com/advisory/ntap-20240322-0006/ | PatchThird Party AdvisoryVendor Advisory |
| https://github.com/squid-cache/squid/commit/72a3bbd5e431597c3fdb56d752bc56b010ba3817 | PatchVendor Advisory |
| https://github.com/squid-cache/squid/security/advisories/GHSA-h5x6-w8mv-xfpr | MitigationThird Party AdvisoryVendor Advisory |
| https://security.netapp.com/advisory/ntap-20240322-0006/ | PatchThird Party AdvisoryVendor Advisory |
Track CVE-2024-25617 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-25617), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.