Vulnerability record · CVE-2024-45802 · published 28 October 2024
CVE-2024-45802: Squid proxy input validation and resource lifetime bugs allow DoS
Squid Cache · Squid
Squid, the open source caching proxy, mishandles input validation and resource lifetime in ways that let a trusted upstream server cause a denial of service against all clients using the proxy. The flaw is fixed in the default build configuration of Squid 6.10, so unpatched proxies remain exposed.
Description
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityNetwork-reachable denial of service with no authentication or interaction required and a high EPSS score, though impact is limited to availability and a fix exists.
What it is
Squid, the open source caching proxy, mishandles input validation and resource lifetime in ways that let a trusted upstream server cause a denial of service against all clients using the proxy. The flaw is fixed in the default build configuration of Squid 6.10, so unpatched proxies remain exposed.
Impact
An attacker controlling a trusted server can degrade or halt proxy service for every client relying on it, disrupting web access rather than gaining code execution or data access.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N); the malicious party is a trusted server the proxy communicates with, not an anonymous internet client.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.479 (98.8th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Upgrade Squid to version 6.10 or later, which fixes the bug in the default build configuration.
- If immediate upgrade is not possible, apply the vendor mitigation guidance in advisory GHSA-f975-v7qw-q7hj.
- Track downstream vendor advisories (Debian LTS, NetApp) for backported packages covering your deployment.
- Limit which upstream servers the proxy is allowed to contact and monitor trusted-server traffic for abnormal resource consumption.
Detection
- Monitor Squid process memory and file descriptor usage for abnormal growth or exhaustion.
- Alert on proxy availability drops, worker restarts, or client connection failures clustered around specific upstream servers.
- Review Squid cache and error logs for repeated failures tied to a single trusted origin server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-45802 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-45802), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.