← Vulnerability feed

Vulnerability record · CVE-2024-25617 · published 14 February 2024

CVE-2024-25617: Squid HTTP header parsing denial of service via oversized headers

Squid Cache · Squid

Squid, the open source caching proxy, mishandles oversized HTTP headers due to a Collapse of Data into Unsafe Value bug in header parsing. A remote client or remote server can send oversized headers to trigger a denial of service. In Squid versions before 6.5 this works with default request_header_max_size and reply_header_max_size settings; 6.5 changed the defaults to safe values.

7.5 CVSS 3.1 High EPSS 88% · top 0.2% CWE-182 · CWE-182CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. In versions of Squid prior to 6.5 this can be achieved if the request_header_max_size or reply_header_max_size settings are unchanged from the default. In Squid version 6.5 and later, the default setting of these parameters is safe. Squid will emit a critical warning in cache.log if the administrator is setting these parameters to unsafe values. Squid will not at this time prevent these settings from being changed to unsafe values. Users are advised to upgrade to version 6.5. There are no known workarounds for this vulnerability. This issue is also tracked as SQUID-2024:2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 7.5 high severity with network reachability, no authentication or interaction needed, and a very high EPSS score, though impact is limited to denial of service.

What it is

Squid, the open source caching proxy, mishandles oversized HTTP headers due to a Collapse of Data into Unsafe Value bug in header parsing. A remote client or remote server can send oversized headers to trigger a denial of service. In Squid versions before 6.5 this works with default request_header_max_size and reply_header_max_size settings; 6.5 changed the defaults to safe values.

Impact

An attacker can cause a denial of service, disrupting proxy availability for all users relying on the affected Squid instance. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

Reachable over the network by any remote client or remote server that can send HTTP messages to the proxy, with no authentication or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). Exploitation depends on the header size limits being at unsafe values, which is the default in versions prior to 6.5.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.88094 (99.758th percentile), indicating substantial predicted exploitation activity. References include patch and vendor advisory links, with no public exploit tag present in the record.

What to do

  • Upgrade Squid to version 6.5 or later, which sets safe defaults for request_header_max_size and reply_header_max_size.
  • If upgrade is not immediately possible, manually set request_header_max_size and reply_header_max_size to safe values and watch cache.log for the critical warning Squid emits when unsafe values are configured.
  • Apply the vendor patch commit referenced in the advisory for environments that cannot move to 6.5.
  • For NetApp BlueXP deployments, apply the fixes in NetApp advisory ntap-20240322-0006.
  • Monitor cache.log for the critical warning about unsafe header size settings as an ongoing control.

Detection

  • Alert on the Squid cache.log critical warning indicating request_header_max_size or reply_header_max_size are set to unsafe values.
  • Monitor proxy availability and restart patterns for unexplained outages consistent with header-parsing resource exhaustion.
  • Inspect HTTP traffic for abnormally large header blocks sent to or from the proxy.
  • Track Squid version inventory to identify instances still running versions prior to 6.5.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25617 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54574Squid-cache squid heap-based buffer overflow vulnerabilitySquid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution att…EPSS 23%9.8CVE-2022-42889Apache Commons Text interpolation allows remote code executionApache Commons Text versions 1.5 through 1.9 enable default StringLookup interpolators (script, dns, url) that can execute code or contact remote ser…EPSS 100%analysed9.8CVE-2020-11945Squid-cache squid integer overflow vulnerabilityAn issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar…EPSS 27%9.8CVE-2019-12519Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function …EPSS 6.7%9.8CVE-2019-12524Squid-cache squid missing authentication for critical function vulnerabilityAn issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid…EPSS 4.3%9.8CVE-2019-12526Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a rem…EPSS 20%9.8CVE-2019-12525Squid-cache squid out-of-bounds write vulnerabilityAn issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the heade…EPSS 24%9.2CVE-2026-33526Squid-cache squid use after free vulnerabilitySquid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP tr…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2024-25617), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.