Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    Musk Furious After SpaceX Stock Get Worst Possible Environmental Grade

    June 22, 2026

    This modular robot mower handles up to 6 acres, and it’s $1,000 off for Prime Day

    June 22, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
    Cybersecurity

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    The Tech GuyBy The Tech GuyJune 22, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Security researchers at Calif.io have disclosed a memory leak vulnerability in Squid Proxy that has existed in the software since 1997. 

    Advertisement

    Squid is a widely used open source web proxy that can reduce bandwidth and improve response times via caching. Squid supports HTTP, HTTPS, FTP, and other protocols.

    Calif researchers discovered that Squid is affected by a vulnerability that is similar to the notorious OpenSSL vulnerability known as Heartbleed, which is why they have dubbed it Squidbleed.

    Officially tracked as CVE-2026-47729, the vulnerability causes Squid’s FTP parser to read beyond the boundary of a memory buffer, into a region that may contain a previous user’s uncleared HTTP request data.

    Exploitation requires the attacker to control an FTP server reachable from the proxy. Squidbleed poses the biggest risk in shared proxy environments, such as corporate networks, schools, and public Wi-Fi hotspots, where multiple users may route traffic via the same Squid instance. 

    An attacker with access to such a network could silently siphon HTTP request data belonging to other users, potentially capturing authentication credentials, session tokens, and API keys. 

    Advertisement. Scroll to continue reading.

    The exposure is limited to cleartext HTTP traffic and deployments where Squid terminates TLS. Standard HTTPS connections relayed as opaque Connect tunnels are not affected. While that reduces the overall attack surface, sensitive credentials can still travel in cleartext HTTP in many enterprise and legacy environments.

    The vulnerability was discovered with the aid of Anthropic’s Claude Mythos AI model.

    A patch was merged into Squid version 8 in April 2026 and shipped in version 7.6 in June 2026. The risk can be mitigated by disabling FTP support entirely if it’s not needed.

    Calif researchers also recently found a high-severity vulnerability in OpenSSL and a DoS attack technique called HTTP/2 Bomb, which allows an attacker to quickly knock web servers offline. Both vulnerabilities were discovered using AI. 

    Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

    Related: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

    Related: Majority of Internet-Accessible REDCap Servers Outdated

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

    June 22, 2026

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

    June 20, 2026

    Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

    June 20, 2026

    French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

    June 20, 2026

    Cybersecurity Firms Impacted by Klue Supply Chain Attack

    June 20, 2026

    CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

    June 19, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    Musk Furious After SpaceX Stock Get Worst Possible Environmental Grade

    June 22, 2026

    This modular robot mower handles up to 6 acres, and it’s $1,000 off for Prime Day

    June 22, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.